CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-1999-1236

    Last Modified: 16 Apr 2026

    Internet Anywhere Mail Server 2.3.1 stores passwords in plaintext in the msgboxes.dbf file, which could allow local users to gain privileges by extracting the passwords from msgboxes.dbf.

    Published: 1 Oct 1999
    5
    Medium

    CVE-2000-0016

    Last Modified: 16 Apr 2026

    Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute commands via a long username.

    Published: 1 Oct 1999
    5
    Medium

    CVE-2000-0047

    Last Modified: 16 Apr 2026

    Buffer overflow in Yahoo Pager/Messenger client allows remote attackers to cause a denial of service via a long URL within a message.

    Published: 1 Oct 1999
    4.3
    Medium

    CVE-1999-0877

    Last Modified: 16 Apr 2026

    Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.

    Published: 1 Oct 1999
    10
    Critical

    CVE-1999-0879

    Last Modified: 16 Apr 2026

    Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.

    Published: 1 Oct 1999
    7.2
    High

    CVE-1999-1583

    Last Modified: 16 Apr 2026

    Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.

    Published: 30 Sept 1999
    7.5
    High

    CVE-1999-1469

    Last Modified: 16 Apr 2026

    Buffer overflow in w3-auth CGI program in miniSQL package allows remote attackers to execute arbitrary commands via an HTTP request with (1) a long URL, or (2) a long User-Agent MIME header.

    Published: 30 Sept 1999
    7.2
    High

    CVE-1999-0932

    Last Modified: 16 Apr 2026

    Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file.

    Published: 30 Sept 1999
    5
    Medium

    CVE-1999-0931

    Last Modified: 16 Apr 2026

    Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.

    Published: 30 Sept 1999
    5
    Medium

    CVE-1999-0289

    Last Modified: 16 Apr 2026

    The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.

    Published: 29 Sept 1999
    4.6
    Medium

    CVE-1999-1350

    Last Modified: 16 Apr 2026

    ARCAD Systemhaus 0.078-5 installs critical programs and files with world-writeable permissions, which could allow local users to gain privileges by replacing a program with a Trojan horse.

    Published: 29 Sept 1999
    10
    Critical

    CVE-1999-0789

    Last Modified: 16 Apr 2026

    Buffer overflow in AIX ftpd in the libc library.

    Published: 28 Sept 1999
    4.6
    Medium

    CVE-1999-1352

    Last Modified: 16 Apr 2026

    mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.

    Published: 28 Sept 1999
    7.5
    High

    CVE-1999-1576

    Last Modified: 16 Apr 2026

    Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to execute arbitrary code via the pdf.setview method.

    Published: 27 Sept 1999
    7.5
    High

    CVE-1999-0940

    Last Modified: 16 Apr 2026

    Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.

    Published: 27 Sept 1999
    5
    Medium

    CVE-1999-0788

    Last Modified: 16 Apr 2026

    Arkiea nlservd allows remote attackers to conduct a denial of service.

    Published: 26 Sept 1999
    5
    Medium

    CVE-1999-1351

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the "Listen to !nick <soundname> requests" option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request.

    Published: 24 Sept 1999
    5.1
    Medium

    CVE-1999-1578

    Last Modified: 16 Apr 2026

    Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.

    Published: 24 Sept 1999
    7.5
    High

    CVE-1999-1484

    Last Modified: 16 Apr 2026

    Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.

    Published: 24 Sept 1999
    5
    Medium

    CVE-1999-0908

    Last Modified: 16 Apr 2026

    Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.

    Published: 23 Sept 1999
    7.5
    High

    CVE-1999-0777

    Last Modified: 16 Apr 2026

    IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.

    Published: 23 Sept 1999
    7.2
    High

    CVE-1999-1534

    Last Modified: 16 Apr 2026

    Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable.

    Published: 23 Sept 1999
    7.2
    High

    CVE-1999-0906

    Last Modified: 16 Apr 2026

    Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.

    Published: 23 Sept 1999
    7.2
    High

    CVE-1999-1013

    Last Modified: 16 Apr 2026

    named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.

    Published: 23 Sept 1999
    7.2
    High

    CVE-1999-1477

    Last Modified: 16 Apr 2026

    Buffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in programs such as nethack.

    Published: 23 Sept 1999
    4.6
    Medium

    CVE-1999-0786

    Last Modified: 16 Apr 2026

    The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.

    Published: 22 Sept 1999
    2.1
    Low

    CVE-1999-0912

    Last Modified: 16 Apr 2026

    FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.

    Published: 22 Sept 1999
    7.2
    High

    CVE-1999-0708

    Last Modified: 16 Apr 2026

    Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.

    Published: 21 Sept 1999
    7.5
    High

    CVE-1999-0909

    Last Modified: 16 Apr 2026

    Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.

    Published: 20 Sept 1999
    9
    Critical

    CVE-1999-0886

    Last Modified: 16 Apr 2026

    The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.

    Published: 17 Sept 1999
    2.1
    Low

    CVE-1999-0787

    Last Modified: 16 Apr 2026

    The SSH authentication agent follows symlinks via a UNIX domain socket.

    Published: 17 Sept 1999
    7.2
    High

    CVE-2000-0824

    Last Modified: 16 Apr 2026

    The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.

    Published: 17 Sept 1999
    9.3
    Critical

    CVE-1999-0704

    Last Modified: 16 Apr 2026

    Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.

    Published: 16 Sept 1999
    2.1
    Low

    CVE-1999-0907

    Last Modified: 16 Apr 2026

    sccw allows local users to read arbitrary files.

    Published: 16 Sept 1999
    10
    Critical

    CVE-1999-0953

    Last Modified: 16 Apr 2026

    WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.

    Published: 16 Sept 1999
    7.5
    High

    CVE-1999-0954

    Last Modified: 16 Apr 2026

    WWWBoard has a default username and default password.

    Published: 16 Sept 1999
    7.5
    High

    CVE-1999-0890

    Last Modified: 16 Apr 2026

    iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.

    Published: 16 Sept 1999
    10
    Critical

    CVE-1999-0817

    Last Modified: 16 Apr 2026

    Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.

    Published: 15 Sept 1999
    7.5
    High

    CVE-1999-1053

    Last Modified: 16 Apr 2026

    guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".

    Published: 13 Sept 1999
    7.2
    High

    CVE-1999-0689

    Last Modified: 16 Apr 2026

    The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.

    Published: 13 Sept 1999
    5.1
    Medium

    CVE-1999-0750

    Last Modified: 16 Apr 2026

    Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account.

    Published: 13 Sept 1999
    5
    Medium

    CVE-1999-0751

    Last Modified: 16 Apr 2026

    Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.

    Published: 13 Sept 1999
    10
    Critical

    CVE-1999-0759

    Last Modified: 16 Apr 2026

    Buffer overflow in FuseMAIL POP service via long USER and PASS commands.

    Published: 13 Sept 1999
    4.6
    Medium

    CVE-1999-1014

    Last Modified: 16 Apr 2026

    Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.

    Published: 13 Sept 1999
    7.5
    High

    CVE-1999-0687

    Last Modified: 16 Apr 2026

    The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.

    Published: 13 Sept 1999
    7.2
    High

    CVE-1999-0691

    Last Modified: 16 Apr 2026

    Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.

    Published: 13 Sept 1999
    10
    Critical

    CVE-1999-1521

    Last Modified: 16 Apr 2026

    Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attacker to execute arbitrary code on the server.

    Published: 12 Sept 1999
    5.1
    Medium

    CVE-1999-1575

    Last Modified: 16 Apr 2026

    The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active Setup (setupctl.dll) ActiveX controls for Internet Explorer (IE) 4.01 and 5.0 are marked as "Safe for Scripting," which allows remote attackers to create and modify files and execute arbitrary commands.

    Published: 10 Sept 1999
    10
    Critical

    CVE-1999-0702

    Last Modified: 16 Apr 2026

    Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.

    Published: 10 Sept 1999
    5
    Medium

    CVE-1999-0910

    Last Modified: 16 Apr 2026

    Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.

    Published: 10 Sept 1999