CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2000-0062

    Last Modified: 16 Apr 2026

    The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.

    Published: 4 Jan 2000
    7.5
    High

    CVE-2000-0085

    Last Modified: 16 Apr 2026

    Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.

    Published: 4 Jan 2000
    10
    Critical

    CVE-1999-0876

    Last Modified: 16 Apr 2026

    Buffer overflow in Internet Explorer 4.0 via EMBED tag.

    Published: 4 Jan 2000
    7.2
    High

    CVE-1999-0979

    Last Modified: 16 Apr 2026

    The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into _init before the privileged process is executed.

    Published: 4 Jan 2000
    7.2
    High

    CVE-2000-0049

    Last Modified: 16 Apr 2026

    Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.

    Published: 4 Jan 2000
    4.6
    Medium

    CVE-2000-0050

    Last Modified: 16 Apr 2026

    The Allaire Spectra Webtop allows authenticated users to access other Webtop sections by specifying explicit URLs.

    Published: 4 Jan 2000
    5
    Medium

    CVE-1999-0695

    Last Modified: 16 Apr 2026

    The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack.

    Published: 4 Jan 2000
    7.2
    High

    CVE-1999-0693

    Last Modified: 16 Apr 2026

    Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.

    Published: 4 Jan 2000
    7.2
    High

    CVE-2000-0052

    Last Modified: 16 Apr 2026

    Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.

    Published: 4 Jan 2000
    7.2
    High

    CVE-2000-0077

    Last Modified: 16 Apr 2026

    The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.

    Published: 2 Jan 2000
    7.2
    High

    CVE-2000-0078

    Last Modified: 16 Apr 2026

    The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.

    Published: 2 Jan 2000
    5
    Medium

    CVE-2000-0082

    Last Modified: 16 Apr 2026

    WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML.

    Published: 2 Jan 2000
    2.1
    Low

    CVE-2000-0069

    Last Modified: 16 Apr 2026

    The recover program in Solstice Backup allows local users to restore sensitive files.

    Published: 1 Jan 2000
    7.5
    High

    CVE-2000-0120

    Last Modified: 16 Apr 2026

    The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.

    Published: 1 Jan 2000
    7.2
    High

    CVE-1999-0964

    Last Modified: 16 Apr 2026

    Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable.

    Published: 1 Jan 2000
    5
    Medium

    CVE-1999-0154

    Last Modified: 16 Apr 2026

    IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.

    Published: 31 Dec 1999
    5
    Medium

    CVE-1999-1043

    Last Modified: 16 Apr 2026

    Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).

    Published: 31 Dec 1999
    7.5
    High

    CVE-1999-1055

    Last Modified: 16 Apr 2026

    Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."

    Published: 31 Dec 1999
    7.5
    High

    CVE-1999-1074

    Last Modified: 16 Apr 2026

    Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.

    Published: 31 Dec 1999
    4.6
    Medium

    CVE-1999-1084

    Last Modified: 16 Apr 2026

    The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

    Published: 31 Dec 1999
    7.5
    High

    CVE-1999-1100

    Last Modified: 16 Apr 2026

    Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack.

    Published: 31 Dec 1999
    5
    Medium

    CVE-1999-1132

    Last Modified: 16 Apr 2026

    Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.

    Published: 31 Dec 1999
    5
    Medium

    CVE-1999-1157

    Last Modified: 16 Apr 2026

    Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.

    Published: 31 Dec 1999
    6.4
    Medium

    CVE-1999-1167

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.

    Published: 31 Dec 1999
    7.5
    High

    CVE-1999-1233

    Last Modified: 16 Apr 2026

    IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.

    Published: 31 Dec 1999
    2.1
    Low

    CVE-1999-1259

    Last Modified: 16 Apr 2026

    Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information.

    Published: 31 Dec 1999
    5.1
    Medium

    CVE-1999-1290

    Last Modified: 16 Apr 2026

    Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string.

    Published: 31 Dec 1999
    7.2
    High

    CVE-1999-1307

    Last Modified: 16 Apr 2026

    Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.

    Published: 31 Dec 1999
    4.6
    Medium

    CVE-1999-1320

    Last Modified: 16 Apr 2026

    Vulnerability in Novell NetWare 3.x and earlier allows local users to gain privileges via packet spoofing.

    Published: 31 Dec 1999
    7.2
    High

    CVE-1999-1329

    Last Modified: 16 Apr 2026

    Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges.

    Published: 31 Dec 1999
    4.6
    Medium

    CVE-1999-1330

    Last Modified: 16 Apr 2026

    The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.

    Published: 31 Dec 1999
    2.1
    Low

    CVE-1999-1331

    Last Modified: 16 Apr 2026

    netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface.

    Published: 31 Dec 1999
    2.1
    Low

    CVE-1999-1332

    Last Modified: 16 Apr 2026

    gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.

    Published: 31 Dec 1999
    7.2
    High

    CVE-1999-1327

    Last Modified: 16 Apr 2026

    Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable.

    Published: 31 Dec 1999
    7.2
    High

    CVE-1999-1328

    Last Modified: 16 Apr 2026

    linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack.

    Published: 31 Dec 1999
    4.6
    Medium

    CVE-1999-1358

    Last Modified: 16 Apr 2026

    When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.

    Published: 31 Dec 1999
    2.1
    Low

    CVE-1999-1363

    Last Modified: 16 Apr 2026

    Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool.

    Published: 31 Dec 1999
    2.1
    Low

    CVE-1999-1364

    Last Modified: 16 Apr 2026

    Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.

    Published: 31 Dec 1999
    2.1
    Low

    CVE-1999-1362

    Last Modified: 16 Apr 2026

    Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters.

    Published: 31 Dec 1999
    5
    Medium

    CVE-1999-1444

    Last Modified: 16 Apr 2026

    genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.

    Published: 31 Dec 1999
    5
    Medium

    CVE-1999-1462

    Last Modified: 16 Apr 2026

    Vulnerability in bb-hist.sh CGI History module in Big Brother 1.09b and 1.09c allows remote attackers to read portions of arbitrary files.

    Published: 31 Dec 1999
    7.5
    High

    CVE-1999-1465

    Last Modified: 16 Apr 2026

    Vulnerability in Cisco IOS 11.1 through 11.3 with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled input interface to an output interface with a logical subinterface, as described by Cisco bug CSCdk43862.

    Published: 31 Dec 1999
    2.1
    Low

    CVE-1999-1476

    Last Modified: 16 Apr 2026

    A bug in Intel Pentium processor (MMX and Overdrive) allows local users to cause a denial of service (hang) in Intel-based operating systems such as Windows NT and Windows 95, via an invalid instruction, aka the "Invalid Operand with Locked CMPXCHG8B Instruction" problem.

    Published: 31 Dec 1999
    5
    Medium

    CVE-1999-1473

    Last Modified: 16 Apr 2026

    When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue."

    Published: 31 Dec 1999
    7.5
    High

    CVE-1999-1474

    Last Modified: 16 Apr 2026

    PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide show, when the document is opened in browsers such as Internet Explorer.

    Published: 31 Dec 1999
    10
    Critical

    CVE-1999-1512

    Last Modified: 16 Apr 2026

    The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.

    Published: 31 Dec 1999
    2.1
    Low

    CVE-1999-1587

    Last Modified: 16 Apr 2026

    /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.

    Published: 31 Dec 1999
    7.2
    High

    CVE-1999-1589

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.

    Published: 31 Dec 1999
    5
    Medium

    CVE-1999-0815

    Last Modified: 16 Apr 2026

    Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.

    Published: 31 Dec 1999
    5.1
    Medium

    CVE-1999-1093

    Last Modified: 16 Apr 2026

    Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.

    Published: 31 Dec 1999