CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2000-0353

    Last Modified: 16 Apr 2026

    Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.

    Published: 28 Jun 1999
    7.2
    High

    CVE-1999-1365

    Last Modified: 16 Apr 2026

    Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.

    Published: 28 Jun 1999
    7.5
    High

    CVE-1999-0938

    Last Modified: 16 Apr 2026

    MBone SDR Package allows remote attackers to execute commands via shell metacharacters in Session Initiation Protocol (SIP) messages.

    Published: 28 Jun 1999
    7.2
    High

    CVE-1999-0733

    Last Modified: 16 Apr 2026

    Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.

    Published: 26 Jun 1999
    7.2
    High

    CVE-1999-0778

    Last Modified: 16 Apr 2026

    Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.

    Published: 25 Jun 1999
    5
    Medium

    CVE-1999-1164

    Last Modified: 16 Apr 2026

    Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.

    Published: 25 Jun 1999
    5
    Medium

    CVE-2005-2458

    Last Modified: 16 Apr 2026

    inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 allows remote attackers to cause a denial of service (kernel crash) via a compressed file with "improper tables".

    Published: 25 Jun 1999
    7.5
    High

    CVE-1999-0748

    Last Modified: 16 Apr 2026

    Buffer overflows in Red Hat net-tools package.

    Published: 24 Jun 1999
    4.6
    Medium

    CVE-1999-1470

    Last Modified: 16 Apr 2026

    Eastman Work Management 3.21 stores passwords in cleartext in the COMMON and LOCATOR registry keys, which could allow local users to gain privileges.

    Published: 24 Jun 1999
    7.2
    High

    CVE-1999-1019

    Last Modified: 16 Apr 2026

    SpectroSERVER in Cabletron Spectrum Enterprise Manager 5.0 installs a directory tree with insecure permissions, which allows local users to replace a privileged executable (processd) with a Trojan horse, facilitating a root or Administrator compromise.

    Published: 23 Jun 1999
    4.6
    Medium

    CVE-1999-0731

    Last Modified: 16 Apr 2026

    The KDE klock program allows local users to unlock a session using malformed input.

    Published: 23 Jun 1999
    7.1
    High

    CVE-1999-0723

    Last Modified: 16 Apr 2026

    The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.

    Published: 23 Jun 1999
    5
    Medium

    CVE-1999-0742

    Last Modified: 16 Apr 2026

    The Debian mailman package uses weak authentication, which allows attackers to gain privileges.

    Published: 22 Jun 1999
    5
    Medium

    CVE-1999-0929

    Last Modified: 16 Apr 2026

    Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests.

    Published: 16 Jun 1999
    10
    Critical

    CVE-1999-0874

    Last Modified: 16 Apr 2026

    Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.

    Published: 16 Jun 1999
    10
    Critical

    CVE-1999-0730

    Last Modified: 16 Apr 2026

    The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.

    Published: 12 Jun 1999
    7.2
    High

    CVE-1999-0713

    Last Modified: 16 Apr 2026

    The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.

    Published: 11 Jun 1999
    10
    Critical

    CVE-1999-0775

    Last Modified: 16 Apr 2026

    Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list.

    Published: 10 Jun 1999
    4.6
    Medium

    CVE-1999-1023

    Last Modified: 16 Apr 2026

    useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired.

    Published: 10 Jun 1999
    7.2
    High

    CVE-2000-0118

    Last Modified: 16 Apr 2026

    The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.

    Published: 9 Jun 1999
    5
    Medium

    CVE-1999-1231

    Last Modified: 16 Apr 2026

    ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.

    Published: 9 Jun 1999
    2.1
    Low

    CVE-1999-1496

    Last Modified: 16 Apr 2026

    Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.

    Published: 8 Jun 1999
    7.5
    High

    CVE-1999-0493

    Last Modified: 16 Apr 2026

    rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.

    Published: 7 Jun 1999
    10
    Critical

    CVE-1999-1237

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.

    Published: 6 Jun 1999
    5
    Medium

    CVE-1999-0970

    Last Modified: 16 Apr 2026

    The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created.

    Published: 5 Jun 1999
    5
    Medium

    CVE-1999-1412

    Last Modified: 16 Apr 2026

    A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.

    Published: 3 Jun 1999
    2.1
    Low

    CVE-1999-1400

    Last Modified: 16 Apr 2026

    The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked.

    Published: 3 Jun 1999
    5
    Medium

    CVE-2000-0481

    Last Modified: 16 Apr 2026

    Buffer overflow in KDE Kmail allows a remote attacker to cause a denial of service via an attachment with a long file name.

    Published: 1 Jun 1999
    7.2
    High

    CVE-2000-0373

    Last Modified: 16 Apr 2026

    Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges.

    Published: 1 Jun 1999
    4.6
    Medium

    CVE-2000-0364

    Last Modified: 16 Apr 2026

    screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.

    Published: 1 Jun 1999
    5
    Medium

    CVE-1999-0804

    Last Modified: 16 Apr 2026

    Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.

    Published: 1 Jun 1999
    6.4
    Medium

    CVE-1999-0772

    Last Modified: 16 Apr 2026

    Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301.

    Published: 1 Jun 1999
    10
    Critical

    CVE-1999-1063

    Last Modified: 16 Apr 2026

    CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.

    Published: 1 Jun 1999
    4.6
    Medium

    CVE-2000-0365

    Last Modified: 16 Apr 2026

    Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.

    Published: 1 Jun 1999
    5
    Medium

    CVE-2000-0333

    Last Modified: 16 Apr 2026

    tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet.

    Published: 31 May 1999
    6.4
    Medium

    CVE-1999-1485

    Last Modified: 16 Apr 2026

    nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system.

    Published: 31 May 1999
    5
    Medium

    CVE-1999-1028

    Last Modified: 16 Apr 2026

    Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.

    Published: 28 May 1999
    5
    Medium

    CVE-1999-0755

    Last Modified: 16 Apr 2026

    Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.

    Published: 27 May 1999
    7.6
    High

    CVE-1999-0802

    Last Modified: 16 Apr 2026

    Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.

    Published: 27 May 1999
    5.1
    Medium

    CVE-1999-0917

    Last Modified: 16 Apr 2026

    The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.

    Published: 27 May 1999
    10
    Critical

    CVE-1999-0920

    Last Modified: 16 Apr 2026

    Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.

    Published: 26 May 1999
    5
    Medium

    CVE-1999-0771

    Last Modified: 16 Apr 2026

    The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.

    Published: 26 May 1999
    5
    Medium

    CVE-1999-0927

    Last Modified: 16 Apr 2026

    NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Published: 26 May 1999
    2.1
    Low

    CVE-1999-0803

    Last Modified: 16 Apr 2026

    The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.

    Published: 25 May 1999
    7.2
    High

    CVE-1999-1414

    Last Modified: 16 Apr 2026

    IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.

    Published: 25 May 1999
    2.6
    Low

    CVE-1999-0762

    Last Modified: 16 Apr 2026

    When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information.

    Published: 24 May 1999
    5
    Medium

    CVE-1999-0928

    Last Modified: 16 Apr 2026

    Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.

    Published: 23 May 1999
    4.6
    Medium

    CVE-1999-1393

    Last Modified: 16 Apr 2026

    Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which is normally inaccessible.

    Published: 21 May 1999
    4.6
    Medium

    CVE-1999-0715

    Last Modified: 16 Apr 2026

    Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.

    Published: 20 May 1999
    10
    Critical

    CVE-1999-0765

    Last Modified: 16 Apr 2026

    SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.

    Published: 19 May 1999