| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-1470 | 0.00 | — | 0.00 | Jun 24, 1999 | Eastman Work Management 3.21 stores passwords in cleartext in the COMMON and LOCATOR registry keys, which could allow local users to gain privileges. | |||
| CVE-1999-0723 | 0.01 | — | 0.07 | Jun 23, 1999 | The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input. | |||
| CVE-1999-0731 | 0.00 | — | 0.00 | Jun 23, 1999 | The KDE klock program allows local users to unlock a session using malformed input. | |||
| CVE-1999-1019 | 0.00 | — | 0.00 | Jun 23, 1999 | SpectroSERVER in Cabletron Spectrum Enterprise Manager 5.0 installs a directory tree with insecure permissions, which allows local users to replace a privileged executable (processd) with a Trojan horse, facilitating a root or Administrator compromise. | |||
| CVE-1999-0742 | 0.00 | — | 0.01 | Jun 22, 1999 | The Debian mailman package uses weak authentication, which allows attackers to gain privileges. | |||
| CVE-1999-0874 | 0.09 | — | 0.75 | Jun 16, 1999 | Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. | |||
| CVE-1999-0929 | 0.00 | — | 0.02 | Jun 16, 1999 | Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests. | |||
| CVE-1999-0730 | 0.03 | — | 0.04 | Jun 12, 1999 | The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack. | |||
| CVE-1999-0713 | 0.00 | — | 0.00 | Jun 11, 1999 | The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges. | |||
| CVE-1999-0775 | 0.00 | — | 0.03 | Jun 10, 1999 | Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list. | |||
| CVE-1999-1023 | 0.00 | — | 0.00 | Jun 10, 1999 | useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired. | |||
| CVE-1999-1231 | 0.00 | — | 0.01 | Jun 9, 1999 | ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server. | |||
| CVE-2000-0118 | 0.03 | — | 0.01 | Jun 9, 1999 | The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing. | |||
| CVE-1999-1496 | 0.00 | — | 0.01 | Jun 8, 1999 | Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist. | |||
| CVE-1999-0493 | 0.03 | — | 0.04 | Jun 7, 1999 | rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd. | |||
| CVE-1999-1237 | 0.01 | — | 0.08 | Jun 6, 1999 | Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods. | |||
| CVE-1999-0970 | 0.03 | — | 0.03 | Jun 5, 1999 | The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created. | |||
| CVE-1999-1400 | 0.00 | — | 0.00 | Jun 3, 1999 | The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked. | |||
| CVE-1999-1412 | 0.06 | — | 0.36 | Jun 3, 1999 | A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes. | |||
| CVE-1999-0772 | 0.00 | — | 0.02 | Jun 1, 1999 | Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301. | |||
| CVE-1999-0804 | 0.03 | — | 0.06 | Jun 1, 1999 | Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths. | |||
| CVE-1999-1063 | 0.04 | — | 0.13 | Jun 1, 1999 | CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter. | |||
| CVE-2000-0364 | 0.00 | — | 0.00 | Jun 1, 1999 | screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys. | |||
| CVE-2000-0365 | 0.00 | — | 0.00 | Jun 1, 1999 | Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices. | |||
| CVE-2000-0373 | 0.00 | — | 0.00 | Jun 1, 1999 | Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges. | |||
| CVE-2000-0481 | 0.00 | — | 0.02 | Jun 1, 1999 | Buffer overflow in KDE Kmail allows a remote attacker to cause a denial of service via an attachment with a long file name. | |||
| CVE-1999-1485 | 0.03 | — | 0.04 | May 31, 1999 | nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system. | |||
| CVE-2000-0333 | 0.04 | — | 0.08 | May 31, 1999 | tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet. | |||
| CVE-1999-1028 | 0.03 | — | 0.03 | May 28, 1999 | Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631. | |||
| CVE-1999-0755 | 0.04 | — | 0.15 | May 27, 1999 | Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option. | |||
| CVE-1999-0802 | 0.01 | — | 0.10 | May 27, 1999 | Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. | |||
| CVE-1999-0917 | 0.00 | — | 0.06 | May 27, 1999 | The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files. | |||
| CVE-1999-0771 | 0.03 | — | 0.06 | May 26, 1999 | The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack. | |||
| CVE-1999-0920 | 0.06 | — | 0.32 | May 26, 1999 | Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command. | |||
| CVE-1999-0927 | 0.03 | — | 0.06 | May 26, 1999 | NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |||
| CVE-1999-0803 | 0.03 | — | 0.01 | May 25, 1999 | The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack. | |||
| CVE-1999-1414 | 0.03 | — | 0.01 | May 25, 1999 | IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges. | |||
| CVE-1999-0762 | 0.00 | — | 0.01 | May 24, 1999 | When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information. | |||
| CVE-1999-0928 | 0.03 | — | 0.05 | May 23, 1999 | Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL. | |||
| CVE-1999-1393 | 0.00 | — | 0.00 | May 21, 1999 | Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which… | |||
| CVE-1999-0715 | 0.03 | — | 0.03 | May 20, 1999 | Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry. | |||
| CVE-1999-0765 | 0.03 | — | 0.05 | May 19, 1999 | SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor. | |||
| CVE-1999-1030 | 0.04 | — | 0.07 | May 19, 1999 | counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation. | |||
| CVE-1999-1031 | 0.00 | — | 0.02 | May 19, 1999 | counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument. | |||
| CVE-1999-0489 | 0.01 | — | 0.12 | May 17, 1999 | MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. | |||
| CVE-1999-0716 | 0.03 | — | 0.03 | May 17, 1999 | Buffer overflow in Windows NT 4.0 help file utility via a malformed help file. | |||
| CVE-1999-1156 | 0.00 | — | 0.01 | May 17, 1999 | BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns. | |||
| CVE-1999-1510 | 0.08 | — | 0.67 | May 17, 1999 | Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands. | |||
| CVE-1999-1366 | 0.00 | — | 0.00 | May 15, 1999 | Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail. | |||
| CVE-1999-1029 | 0.00 | — | 0.02 | May 13, 1999 | SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs. |
- CVE-1999-1470Jun 24, 1999risk 0.00cvss —epss 0.00
Eastman Work Management 3.21 stores passwords in cleartext in the COMMON and LOCATOR registry keys, which could allow local users to gain privileges.
- CVE-1999-0723Jun 23, 1999risk 0.01cvss —epss 0.07
The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.
- CVE-1999-0731Jun 23, 1999risk 0.00cvss —epss 0.00
The KDE klock program allows local users to unlock a session using malformed input.
- CVE-1999-1019Jun 23, 1999risk 0.00cvss —epss 0.00
SpectroSERVER in Cabletron Spectrum Enterprise Manager 5.0 installs a directory tree with insecure permissions, which allows local users to replace a privileged executable (processd) with a Trojan horse, facilitating a root or Administrator compromise.
- CVE-1999-0742Jun 22, 1999risk 0.00cvss —epss 0.01
The Debian mailman package uses weak authentication, which allows attackers to gain privileges.
- CVE-1999-0874Jun 16, 1999risk 0.09cvss —epss 0.75
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
- CVE-1999-0929Jun 16, 1999risk 0.00cvss —epss 0.02
Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests.
- CVE-1999-0730Jun 12, 1999risk 0.03cvss —epss 0.04
The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.
- CVE-1999-0713Jun 11, 1999risk 0.00cvss —epss 0.00
The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.
- CVE-1999-0775Jun 10, 1999risk 0.00cvss —epss 0.03
Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list.
- CVE-1999-1023Jun 10, 1999risk 0.00cvss —epss 0.00
useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired.
- CVE-1999-1231Jun 9, 1999risk 0.00cvss —epss 0.01
ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.
- CVE-2000-0118Jun 9, 1999risk 0.03cvss —epss 0.01
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
- CVE-1999-1496Jun 8, 1999risk 0.00cvss —epss 0.01
Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.
- CVE-1999-0493Jun 7, 1999risk 0.03cvss —epss 0.04
rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.
- CVE-1999-1237Jun 6, 1999risk 0.01cvss —epss 0.08
Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.
- CVE-1999-0970Jun 5, 1999risk 0.03cvss —epss 0.03
The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created.
- CVE-1999-1400Jun 3, 1999risk 0.00cvss —epss 0.00
The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked.
- CVE-1999-1412Jun 3, 1999risk 0.06cvss —epss 0.36
A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.
- CVE-1999-0772Jun 1, 1999risk 0.00cvss —epss 0.02
Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301.
- CVE-1999-0804Jun 1, 1999risk 0.03cvss —epss 0.06
Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.
- CVE-1999-1063Jun 1, 1999risk 0.04cvss —epss 0.13
CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.
- CVE-2000-0364Jun 1, 1999risk 0.00cvss —epss 0.00
screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.
- CVE-2000-0365Jun 1, 1999risk 0.00cvss —epss 0.00
Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.
- CVE-2000-0373Jun 1, 1999risk 0.00cvss —epss 0.00
Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges.
- CVE-2000-0481Jun 1, 1999risk 0.00cvss —epss 0.02
Buffer overflow in KDE Kmail allows a remote attacker to cause a denial of service via an attachment with a long file name.
- CVE-1999-1485May 31, 1999risk 0.03cvss —epss 0.04
nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system.
- CVE-2000-0333May 31, 1999risk 0.04cvss —epss 0.08
tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet.
- CVE-1999-1028May 28, 1999risk 0.03cvss —epss 0.03
Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.
- CVE-1999-0755May 27, 1999risk 0.04cvss —epss 0.15
Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.
- CVE-1999-0802May 27, 1999risk 0.01cvss —epss 0.10
Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.
- CVE-1999-0917May 27, 1999risk 0.00cvss —epss 0.06
The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.
- CVE-1999-0771May 26, 1999risk 0.03cvss —epss 0.06
The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.
- CVE-1999-0920May 26, 1999risk 0.06cvss —epss 0.32
Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.
- CVE-1999-0927May 26, 1999risk 0.03cvss —epss 0.06
NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.
- CVE-1999-0803May 25, 1999risk 0.03cvss —epss 0.01
The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.
- CVE-1999-1414May 25, 1999risk 0.03cvss —epss 0.01
IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.
- CVE-1999-0762May 24, 1999risk 0.00cvss —epss 0.01
When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information.
- CVE-1999-0928May 23, 1999risk 0.03cvss —epss 0.05
Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.
- CVE-1999-1393May 21, 1999risk 0.00cvss —epss 0.00
Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which…
- CVE-1999-0715May 20, 1999risk 0.03cvss —epss 0.03
Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.
- CVE-1999-0765May 19, 1999risk 0.03cvss —epss 0.05
SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.
- CVE-1999-1030May 19, 1999risk 0.04cvss —epss 0.07
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation.
- CVE-1999-1031May 19, 1999risk 0.00cvss —epss 0.02
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument.
- CVE-1999-0489May 17, 1999risk 0.01cvss —epss 0.12
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.
- CVE-1999-0716May 17, 1999risk 0.03cvss —epss 0.03
Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.
- CVE-1999-1156May 17, 1999risk 0.00cvss —epss 0.01
BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns.
- CVE-1999-1510May 17, 1999risk 0.08cvss —epss 0.67
Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands.
- CVE-1999-1366May 15, 1999risk 0.00cvss —epss 0.00
Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.
- CVE-1999-1029May 13, 1999risk 0.00cvss —epss 0.02
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.