CVE-1999-1591
Last Modified: 16 Apr 2026Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0.
CVE-1999-1102
Last Modified: 16 Apr 2026lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.
CVE-1999-1124
Last Modified: 16 Apr 2026HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the request is coming from the local host.
CVE-1999-1223
Last Modified: 16 Apr 2026IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.
CVE-1999-1300
Last Modified: 16 Apr 2026Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounting configuration.
CVE-1999-1317
Last Modified: 16 Apr 2026Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.
CVE-1999-1452
Last Modified: 16 Apr 2026GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt.
CVE-1999-1585
Last Modified: 16 Apr 2026The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.
CVE-1999-0808
Last Modified: 16 Apr 2026Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.
CVE-1999-1087
Last Modified: 16 Apr 2026Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.
CVE-1999-1126
Last Modified: 16 Apr 2026Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with "DPR_".
CVE-1999-1175
Last Modified: 16 Apr 2026Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.
CVE-1999-1333
Last Modified: 16 Apr 2026automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.
CVE-1999-1481
Last Modified: 16 Apr 2026Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.
CVE-1999-1222
Last Modified: 16 Apr 2026Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.
CVE-1999-1042
Last Modified: 16 Apr 2026Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.
CVE-1999-1127
Last Modified: 16 Apr 2026Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.
CVE-1999-1315
Last Modified: 16 Apr 2026Vulnerabilities in DECnet/OSI for OpenVMS before 5.8 on DEC Alpha AXP and VAX/VMS systems allow local users to gain privileges or cause a denial of service.
CVE-1999-1379
Last Modified: 16 Apr 2026DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker.
CVE-1999-1386
Last Modified: 16 Apr 2026Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.
CVE-1999-1584
Last Modified: 16 Apr 2026Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586.
CVE-1999-1592
Last Modified: 16 Apr 2026Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact. NOTE: this might overlap CVE-1999-0129.
CVE-2000-0003
Last Modified: 16 Apr 2026Buffer overflow in UnixWare rtpm program allows local users to gain privileges via a long environmental variable.
CVE-2000-0043
Last Modified: 16 Apr 2026Buffer overflow in CamShot WebCam HTTP server allows remote attackers to execute commands via a long GET request.
CVE-2000-0076
Last Modified: 16 Apr 2026nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.
CVE-1999-0001
Last Modified: 16 Apr 2026ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.
CVE-2000-0007
Last Modified: 16 Apr 2026Trend Micro PC-Cillin does not restrict access to its internal proxy port, allowing remote attackers to conduct a denial of service.
CVE-2000-0042
Last Modified: 16 Apr 2026Buffer overflow in CSM mail server allows remote attackers to cause a denial of service or execute commands via a long HELO command.
CVE-2000-0009
Last Modified: 16 Apr 2026The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which allows local users to execute arbitrary commands.
CVE-2000-0039
Last Modified: 16 Apr 2026AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program.
CVE-2000-0100
Last Modified: 16 Apr 2026The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.
CVE-1999-1573
Last Modified: 16 Apr 2026Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.
CVE-2000-0014
Last Modified: 16 Apr 2026Denial of service in Savant web server via a null character in the requested URL.
CVE-2000-0041
Last Modified: 16 Apr 2026Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.
CVE-2000-0035
Last Modified: 16 Apr 2026resend command in Majordomo allows local users to gain privileges via shell metacharacters.
CVE-2000-0037
Last Modified: 16 Apr 2026Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.
CVE-2000-0027
Last Modified: 16 Apr 2026IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.
CVE-2000-0029
Last Modified: 16 Apr 2026UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.
CVE-2000-0033
Last Modified: 16 Apr 2026InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.
CVE-2000-0060
Last Modified: 16 Apr 2026Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name.
CVE-2000-0012
Last Modified: 16 Apr 2026Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.
CVE-2000-0008
Last Modified: 16 Apr 2026FTPPro allows local users to read sensitive information, which is stored in plain text.
CVE-2000-0010
Last Modified: 16 Apr 2026WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.
CVE-1999-0477
Last Modified: 16 Apr 2026The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
CVE-2000-0006
Last Modified: 16 Apr 2026strace allows local users to read arbitrary files via memory mapped file names.
CVE-1999-0455
Last Modified: 16 Apr 2026The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.
CVE-1999-0892
Last Modified: 16 Apr 2026Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.
CVE-2000-0001
Last Modified: 16 Apr 2026RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.
CVE-2000-0028
Last Modified: 16 Apr 2026Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.
CVE-2000-0038
Last Modified: 16 Apr 2026glFtpD includes a default glftpd user account with a default password and a UID of 0.
