CVE-1999-0749
Last Modified: 16 Apr 2026Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.
CVE-1999-0888
Last Modified: 16 Apr 2026dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.
CVE-1999-0679
Last Modified: 16 Apr 2026Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.
CVE-1999-0724
Last Modified: 16 Apr 2026Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.
CVE-1999-1336
Last Modified: 16 Apr 20263Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port.
CVE-1999-0867
Last Modified: 16 Apr 2026Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
CVE-1999-0875
Last Modified: 16 Apr 2026DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
CVE-1999-0861
Last Modified: 16 Apr 2026Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
CVE-1999-0694
Last Modified: 16 Apr 2026Denial of service in AIX ptrace system call allows local users to crash the system.
CVE-1999-0814
Last Modified: 16 Apr 2026Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.
CVE-1999-0813
Last Modified: 16 Apr 2026Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.
CVE-1999-0680
Last Modified: 16 Apr 2026Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.
CVE-1999-0674
Last Modified: 16 Apr 2026The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
CVE-1999-0675
Last Modified: 16 Apr 2026Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.
CVE-1999-0676
Last Modified: 16 Apr 2026sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
CVE-1999-0722
Last Modified: 16 Apr 2026The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.
CVE-1999-0673
Last Modified: 16 Apr 2026Buffer overflow in ALMail32 POP3 client via From: or To: headers.
CVE-1999-1524
Last Modified: 16 Apr 2026FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.
CVE-1999-0682
Last Modified: 16 Apr 2026Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.
CVE-1999-0727
Last Modified: 16 Apr 2026A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.
CVE-1999-0913
Last Modified: 16 Apr 2026dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.
CVE-1999-0671
Last Modified: 16 Apr 2026Buffer overflow in ToxSoft NextFTP client through CWD command.
CVE-1999-0677
Last Modified: 16 Apr 2026The WebRamp web administration utility has a default password.
CVE-1999-0703
Last Modified: 16 Apr 2026OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.
CVE-1999-0672
Last Modified: 16 Apr 2026Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.
CVE-1999-1337
Last Modified: 16 Apr 2026FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.
CVE-1999-0683
Last Modified: 16 Apr 2026Denial of service in Gauntlet Firewall via a malformed ICMP packet.
CVE-1999-1227
Last Modified: 16 Apr 2026Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.
CVE-1999-1536
Last Modified: 16 Apr 2026.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.
CVE-1999-1130
Last Modified: 16 Apr 2026Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.
CVE-1999-0700
Last Modified: 16 Apr 2026Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
CVE-1999-0770
Last Modified: 16 Apr 2026Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.
CVE-1999-1078
Last Modified: 16 Apr 2026WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.
CVE-2000-0323
Last Modified: 16 Apr 2026The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.
CVE-1999-1017
Last Modified: 16 Apr 2026Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.
CVE-1999-1018
Last Modified: 16 Apr 2026IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.
CVE-1999-0710
Last Modified: 16 Apr 2026The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.
CVE-1999-0224
Last Modified: 16 Apr 2026Denial of service in Windows NT messenger service through a long username.
CVE-1999-0719
Last Modified: 16 Apr 2026The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.
CVE-1999-1338
Last Modified: 16 Apr 2026Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.
CVE-1999-1165
Last Modified: 16 Apr 2026GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.
CVE-1999-0810
Last Modified: 16 Apr 2026Denial of service in Samba NETBIOS name service daemon (nmbd).
CVE-1999-0811
Last Modified: 16 Apr 2026Buffer overflow in Samba smbd program via a malformed message command.
CVE-1999-1535
Last Modified: 16 Apr 2026Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request.
CVE-1999-1560
Last Modified: 16 Apr 2026Vulnerability in a script in Texas A&M University (TAMU) Tiger allows local users to execute arbitrary commands as the Tiger user, usually root.
CVE-1999-0721
Last Modified: 16 Apr 2026Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
CVE-1999-1378
Last Modified: 16 Apr 2026dbmlparser.exe CGI guestbook program does not perform a chroot operation properly, which allows remote attackers to read arbitrary files.
CVE-1999-0692
Last Modified: 16 Apr 2026The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.
CVE-1999-1011
Last Modified: 16 Apr 2026The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
CVE-1999-1086
Last Modified: 16 Apr 2026Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls.
