CVE Feed

    Dashboard / CVE

    2.6
    Low

    CVE-1999-0749

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.

    Published: 16 Aug 1999
    4.6
    Medium

    CVE-1999-0888

    Last Modified: 16 Apr 2026

    dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.

    Published: 16 Aug 1999
    7.5
    High

    CVE-1999-0679

    Last Modified: 16 Apr 2026

    Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.

    Published: 13 Aug 1999
    4.6
    Medium

    CVE-1999-0724

    Last Modified: 16 Apr 2026

    Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.

    Published: 12 Aug 1999
    5
    Medium

    CVE-1999-1336

    Last Modified: 16 Apr 2026

    3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port.

    Published: 12 Aug 1999
    5
    Medium

    CVE-1999-0867

    Last Modified: 16 Apr 2026

    Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.

    Published: 11 Aug 1999
    7.5
    High

    CVE-1999-0875

    Last Modified: 16 Apr 2026

    DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.

    Published: 11 Aug 1999
    2.6
    Low

    CVE-1999-0861

    Last Modified: 16 Apr 2026

    Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.

    Published: 11 Aug 1999
    2.1
    Low

    CVE-1999-0694

    Last Modified: 16 Apr 2026

    Denial of service in AIX ptrace system call allows local users to crash the system.

    Published: 11 Aug 1999
    10
    Critical

    CVE-1999-0814

    Last Modified: 16 Apr 2026

    Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.

    Published: 11 Aug 1999
    7.2
    High

    CVE-1999-0813

    Last Modified: 16 Apr 2026

    Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.

    Published: 10 Aug 1999
    5
    Medium

    CVE-1999-0680

    Last Modified: 16 Apr 2026

    Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.

    Published: 9 Aug 1999
    7.2
    High

    CVE-1999-0674

    Last Modified: 16 Apr 2026

    The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.

    Published: 9 Aug 1999
    5
    Medium

    CVE-1999-0675

    Last Modified: 16 Apr 2026

    Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.

    Published: 9 Aug 1999
    4.6
    Medium

    CVE-1999-0676

    Last Modified: 16 Apr 2026

    sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.

    Published: 9 Aug 1999
    10
    Critical

    CVE-1999-0722

    Last Modified: 16 Apr 2026

    The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.

    Published: 8 Aug 1999
    5.1
    Medium

    CVE-1999-0673

    Last Modified: 16 Apr 2026

    Buffer overflow in ALMail32 POP3 client via From: or To: headers.

    Published: 8 Aug 1999
    5
    Medium

    CVE-1999-1524

    Last Modified: 16 Apr 2026

    FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.

    Published: 7 Aug 1999
    5
    Medium

    CVE-1999-0682

    Last Modified: 16 Apr 2026

    Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.

    Published: 6 Aug 1999
    5
    Medium

    CVE-1999-0727

    Last Modified: 16 Apr 2026

    A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.

    Published: 6 Aug 1999
    10
    Critical

    CVE-1999-0913

    Last Modified: 16 Apr 2026

    dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.

    Published: 5 Aug 1999
    5.1
    Medium

    CVE-1999-0671

    Last Modified: 16 Apr 2026

    Buffer overflow in ToxSoft NextFTP client through CWD command.

    Published: 3 Aug 1999
    7.5
    High

    CVE-1999-0677

    Last Modified: 16 Apr 2026

    The WebRamp web administration utility has a default password.

    Published: 3 Aug 1999
    3.6
    Low

    CVE-1999-0703

    Last Modified: 16 Apr 2026

    OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.

    Published: 3 Aug 1999
    5.1
    Medium

    CVE-1999-0672

    Last Modified: 16 Apr 2026

    Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.

    Published: 1 Aug 1999
    4.6
    Medium

    CVE-1999-1337

    Last Modified: 16 Apr 2026

    FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.

    Published: 1 Aug 1999
    5
    Medium

    CVE-1999-0683

    Last Modified: 16 Apr 2026

    Denial of service in Gauntlet Firewall via a malformed ICMP packet.

    Published: 30 Jul 1999
    7.2
    High

    CVE-1999-1227

    Last Modified: 16 Apr 2026

    Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.

    Published: 30 Jul 1999
    7.2
    High

    CVE-1999-1536

    Last Modified: 16 Apr 2026

    .sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.

    Published: 30 Jul 1999
    5
    Medium

    CVE-1999-1130

    Last Modified: 16 Apr 2026

    Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.

    Published: 30 Jul 1999
    6.2
    Medium

    CVE-1999-0700

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.

    Published: 29 Jul 1999
    2.1
    Low

    CVE-1999-0770

    Last Modified: 16 Apr 2026

    Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.

    Published: 29 Jul 1999
    7.5
    High

    CVE-1999-1078

    Last Modified: 16 Apr 2026

    WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.

    Published: 29 Jul 1999
    7.6
    High

    CVE-2000-0323

    Last Modified: 16 Apr 2026

    The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.

    Published: 28 Jul 1999
    7.5
    High

    CVE-1999-1017

    Last Modified: 16 Apr 2026

    Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.

    Published: 28 Jul 1999
    7.5
    High

    CVE-1999-1018

    Last Modified: 16 Apr 2026

    IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.

    Published: 27 Jul 1999
    7.5
    High

    CVE-1999-0710

    Last Modified: 16 Apr 2026

    The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.

    Published: 25 Jul 1999
    5
    Medium

    CVE-1999-0224

    Last Modified: 16 Apr 2026

    Denial of service in Windows NT messenger service through a long username.

    Published: 23 Jul 1999
    4.6
    Medium

    CVE-1999-0719

    Last Modified: 16 Apr 2026

    The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.

    Published: 23 Jul 1999
    5
    Medium

    CVE-1999-1338

    Last Modified: 16 Apr 2026

    Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.

    Published: 21 Jul 1999
    7.2
    High

    CVE-1999-1165

    Last Modified: 16 Apr 2026

    GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.

    Published: 21 Jul 1999
    10
    Critical

    CVE-1999-0810

    Last Modified: 16 Apr 2026

    Denial of service in Samba NETBIOS name service daemon (nmbd).

    Published: 21 Jul 1999
    5
    Medium

    CVE-1999-0811

    Last Modified: 16 Apr 2026

    Buffer overflow in Samba smbd program via a malformed message command.

    Published: 21 Jul 1999
    10
    Critical

    CVE-1999-1535

    Last Modified: 16 Apr 2026

    Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request.

    Published: 20 Jul 1999
    7.2
    High

    CVE-1999-1560

    Last Modified: 16 Apr 2026

    Vulnerability in a script in Texas A&M University (TAMU) Tiger allows local users to execute arbitrary commands as the Tiger user, usually root.

    Published: 20 Jul 1999
    7.8
    High

    CVE-1999-0721

    Last Modified: 16 Apr 2026

    Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.

    Published: 20 Jul 1999
    5
    Medium

    CVE-1999-1378

    Last Modified: 16 Apr 2026

    dbmlparser.exe CGI guestbook program does not perform a chroot operation properly, which allows remote attackers to read arbitrary files.

    Published: 19 Jul 1999
    10
    Critical

    CVE-1999-0692

    Last Modified: 16 Apr 2026

    The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.

    Published: 19 Jul 1999
    10
    Critical

    CVE-1999-1011

    Last Modified: 16 Apr 2026

    The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.

    Published: 19 Jul 1999
    10
    Critical

    CVE-1999-1086

    Last Modified: 16 Apr 2026

    Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls.

    Published: 15 Jul 1999