| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0891 | 0.06 | — | 0.43 | Sep 1, 1999 | The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect. | |||
| CVE-1999-1129 | 0.00 | — | 0.02 | Sep 1, 1999 | Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag. | |||
| CVE-1999-0774 | 0.03 | — | 0.01 | Aug 31, 1999 | Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names. | |||
| CVE-1999-1515 | 0.03 | — | 0.05 | Aug 31, 1999 | A non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender and recipient addresses, which causes the gateway to continuously try to return the message every 10 seconds. | |||
| CVE-1999-1354 | 0.00 | — | 0.00 | Aug 30, 1999 | E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled. | |||
| CVE-1999-1513 | — | 0.00 | — | 0.01 | Aug 30, 1999 | Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string, but lists the entire table of community strings, which could allow attackers to… | ||
| CVE-1999-0911 | 0.06 | — | 0.38 | Aug 27, 1999 | Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. | |||
| CVE-1999-1016 | 0.04 | — | 0.08 | Aug 27, 1999 | Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as… | |||
| CVE-1999-0939 | 0.00 | — | 0.01 | Aug 26, 1999 | Denial of service in Debian IRC Epic/epic4 client via a long string. | |||
| CVE-1999-0768 | 0.03 | — | 0.02 | Aug 25, 1999 | Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable. | |||
| CVE-1999-0769 | 0.03 | — | 0.01 | Aug 25, 1999 | Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable. | |||
| CVE-1999-0872 | 0.00 | — | 0.00 | Aug 25, 1999 | Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file. | |||
| CVE-1999-1235 | 0.03 | — | 0.03 | Aug 25, 1999 | Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the… | |||
| CVE-1999-1052 | 0.01 | — | 0.14 | Aug 24, 1999 | Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users. | |||
| CVE-2000-0328 | 0.02 | — | 0.25 | Aug 24, 1999 | Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking. | |||
| CVE-1999-0720 | 0.03 | — | 0.01 | Aug 23, 1999 | The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users. | |||
| CVE-1999-0878 | 0.00 | — | 0.02 | Aug 22, 1999 | Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR. | |||
| CVE-1999-1064 | 0.00 | — | 0.02 | Aug 22, 1999 | Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]). | |||
| CVE-2000-0374 | 0.00 | — | 0.04 | Aug 22, 1999 | The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions. | |||
| CVE-1999-0668 | 0.05 | — | 0.23 | Aug 21, 1999 | The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. | |||
| CVE-2000-0355 | 0.00 | — | 0.01 | Aug 21, 1999 | pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files. | |||
| CVE-1999-0743 | 0.00 | — | 0.00 | Aug 20, 1999 | Trn allows local users to overwrite other users' files via symlinks. | |||
| CVE-1999-1561 | 0.00 | — | 0.00 | Aug 20, 1999 | Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server. | |||
| CVE-1999-1565 | 0.00 | — | 0.00 | Aug 20, 1999 | Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file. | |||
| CVE-2000-0325 | 0.03 | — | 0.04 | Aug 20, 1999 | The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability. | |||
| CVE-2000-1206 | 0.00 | — | 0.05 | Aug 20, 1999 | Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files. | |||
| CVE-1999-0725 | 0.05 | — | 0.25 | Aug 19, 1999 | When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". | |||
| CVE-1999-0732 | 0.00 | — | 0.00 | Aug 19, 1999 | The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links. | |||
| CVE-1999-0734 | 0.00 | — | 0.01 | Aug 19, 1999 | A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication. | |||
| CVE-1999-0740 | 0.00 | — | 0.02 | Aug 19, 1999 | Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable. | |||
| CVE-1999-0741 | 0.00 | — | 0.02 | Aug 19, 1999 | QMS CrownNet Unix Utilities for 2060 allows root to log on without a password. | |||
| CVE-1999-0745 | 0.03 | — | 0.03 | Aug 18, 1999 | Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler. | |||
| CVE-1999-0747 | 0.00 | — | 0.00 | Aug 18, 1999 | Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load. | |||
| CVE-1999-0753 | 0.03 | — | 0.05 | Aug 17, 1999 | The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories. | |||
| CVE-1999-0746 | 0.03 | — | 0.06 | Aug 16, 1999 | A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service. | |||
| CVE-1999-0749 | 0.04 | — | 0.08 | Aug 16, 1999 | Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument. | |||
| CVE-1999-0888 | 0.03 | — | 0.01 | Aug 16, 1999 | dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script. | |||
| CVE-1999-0679 | 0.03 | — | 0.03 | Aug 13, 1999 | Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option. | |||
| CVE-1999-0724 | 0.00 | — | 0.00 | Aug 12, 1999 | Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function. | |||
| CVE-1999-1336 | — | 0.00 | — | 0.02 | Aug 12, 1999 | 3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port. | ||
| CVE-1999-0694 | 0.00 | — | 0.00 | Aug 11, 1999 | Denial of service in AIX ptrace system call allows local users to crash the system. | |||
| CVE-1999-0814 | 0.00 | — | 0.02 | Aug 11, 1999 | Red Hat pump DHCP client allows remote attackers to gain root access in some configurations. | |||
| CVE-1999-0861 | 0.00 | — | 0.03 | Aug 11, 1999 | Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. | |||
| CVE-1999-0867 | 0.05 | — | 0.22 | Aug 11, 1999 | Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. | |||
| CVE-1999-0875 | 0.04 | — | 0.10 | Aug 11, 1999 | DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes. | |||
| CVE-1999-0813 | 0.00 | — | 0.00 | Aug 10, 1999 | Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges. | |||
| CVE-1999-0674 | 0.03 | — | 0.01 | Aug 9, 1999 | The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve. | |||
| CVE-1999-0675 | 0.00 | — | 0.01 | Aug 9, 1999 | Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host. | |||
| CVE-1999-0676 | 0.00 | — | 0.00 | Aug 9, 1999 | sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack. | |||
| CVE-1999-0680 | 0.00 | — | 0.06 | Aug 9, 1999 | Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service. |
- CVE-1999-0891Sep 1, 1999risk 0.06cvss —epss 0.43
The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.
- CVE-1999-1129Sep 1, 1999risk 0.00cvss —epss 0.02
Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag.
- CVE-1999-0774Aug 31, 1999risk 0.03cvss —epss 0.01
Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.
- CVE-1999-1515Aug 31, 1999risk 0.03cvss —epss 0.05
A non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender and recipient addresses, which causes the gateway to continuously try to return the message every 10 seconds.
- CVE-1999-1354Aug 30, 1999risk 0.00cvss —epss 0.00
E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled.
- CVE-1999-1513Aug 30, 1999risk 0.00cvss —epss 0.01
Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string, but lists the entire table of community strings, which could allow attackers to…
- CVE-1999-0911Aug 27, 1999risk 0.06cvss —epss 0.38
Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.
- CVE-1999-1016Aug 27, 1999risk 0.04cvss —epss 0.08
Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as…
- CVE-1999-0939Aug 26, 1999risk 0.00cvss —epss 0.01
Denial of service in Debian IRC Epic/epic4 client via a long string.
- CVE-1999-0768Aug 25, 1999risk 0.03cvss —epss 0.02
Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.
- CVE-1999-0769Aug 25, 1999risk 0.03cvss —epss 0.01
Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.
- CVE-1999-0872Aug 25, 1999risk 0.00cvss —epss 0.00
Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.
- CVE-1999-1235Aug 25, 1999risk 0.03cvss —epss 0.03
Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the…
- CVE-1999-1052Aug 24, 1999risk 0.01cvss —epss 0.14
Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.
- CVE-2000-0328Aug 24, 1999risk 0.02cvss —epss 0.25
Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.
- CVE-1999-0720Aug 23, 1999risk 0.03cvss —epss 0.01
The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.
- CVE-1999-0878Aug 22, 1999risk 0.00cvss —epss 0.02
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.
- CVE-1999-1064Aug 22, 1999risk 0.00cvss —epss 0.02
Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]).
- CVE-2000-0374Aug 22, 1999risk 0.00cvss —epss 0.04
The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions.
- CVE-1999-0668Aug 21, 1999risk 0.05cvss —epss 0.23
The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.
- CVE-2000-0355Aug 21, 1999risk 0.00cvss —epss 0.01
pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.
- CVE-1999-0743Aug 20, 1999risk 0.00cvss —epss 0.00
Trn allows local users to overwrite other users' files via symlinks.
- CVE-1999-1561Aug 20, 1999risk 0.00cvss —epss 0.00
Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.
- CVE-1999-1565Aug 20, 1999risk 0.00cvss —epss 0.00
Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
- CVE-2000-0325Aug 20, 1999risk 0.03cvss —epss 0.04
The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.
- CVE-2000-1206Aug 20, 1999risk 0.00cvss —epss 0.05
Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
- CVE-1999-0725Aug 19, 1999risk 0.05cvss —epss 0.25
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
- CVE-1999-0732Aug 19, 1999risk 0.00cvss —epss 0.00
The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.
- CVE-1999-0734Aug 19, 1999risk 0.00cvss —epss 0.01
A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.
- CVE-1999-0740Aug 19, 1999risk 0.00cvss —epss 0.02
Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.
- CVE-1999-0741Aug 19, 1999risk 0.00cvss —epss 0.02
QMS CrownNet Unix Utilities for 2060 allows root to log on without a password.
- CVE-1999-0745Aug 18, 1999risk 0.03cvss —epss 0.03
Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.
- CVE-1999-0747Aug 18, 1999risk 0.00cvss —epss 0.00
Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load.
- CVE-1999-0753Aug 17, 1999risk 0.03cvss —epss 0.05
The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.
- CVE-1999-0746Aug 16, 1999risk 0.03cvss —epss 0.06
A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.
- CVE-1999-0749Aug 16, 1999risk 0.04cvss —epss 0.08
Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.
- CVE-1999-0888Aug 16, 1999risk 0.03cvss —epss 0.01
dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.
- CVE-1999-0679Aug 13, 1999risk 0.03cvss —epss 0.03
Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.
- CVE-1999-0724Aug 12, 1999risk 0.00cvss —epss 0.00
Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.
- CVE-1999-1336Aug 12, 1999risk 0.00cvss —epss 0.02
3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port.
- CVE-1999-0694Aug 11, 1999risk 0.00cvss —epss 0.00
Denial of service in AIX ptrace system call allows local users to crash the system.
- CVE-1999-0814Aug 11, 1999risk 0.00cvss —epss 0.02
Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.
- CVE-1999-0861Aug 11, 1999risk 0.00cvss —epss 0.03
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
- CVE-1999-0867Aug 11, 1999risk 0.05cvss —epss 0.22
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
- CVE-1999-0875Aug 11, 1999risk 0.04cvss —epss 0.10
DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
- CVE-1999-0813Aug 10, 1999risk 0.00cvss —epss 0.00
Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.
- CVE-1999-0674Aug 9, 1999risk 0.03cvss —epss 0.01
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
- CVE-1999-0675Aug 9, 1999risk 0.00cvss —epss 0.01
Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.
- CVE-1999-0676Aug 9, 1999risk 0.00cvss —epss 0.00
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
- CVE-1999-0680Aug 9, 1999risk 0.00cvss —epss 0.06
Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.