CVE Feed

    Dashboard / CVE

    1.2
    Low

    CVE-1999-1042

    Last Modified: 16 Apr 2026

    Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.

    Published: 31 Dec 1999
    7.5
    High

    CVE-1999-1127

    Last Modified: 16 Apr 2026

    Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.

    Published: 31 Dec 1999
    4.6
    Medium

    CVE-1999-1315

    Last Modified: 16 Apr 2026

    Vulnerabilities in DECnet/OSI for OpenVMS before 5.8 on DEC Alpha AXP and VAX/VMS systems allow local users to gain privileges or cause a denial of service.

    Published: 31 Dec 1999
    5
    Medium

    CVE-1999-1379

    Last Modified: 16 Apr 2026

    DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker.

    Published: 31 Dec 1999
    5.5
    Medium

    CVE-1999-1386

    Last Modified: 16 Apr 2026

    Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.

    Published: 31 Dec 1999
    10
    Critical

    CVE-1999-1584

    Last Modified: 16 Apr 2026

    Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586.

    Published: 31 Dec 1999
    7.5
    High

    CVE-1999-1592

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact. NOTE: this might overlap CVE-1999-0129.

    Published: 31 Dec 1999
    10
    Critical

    CVE-2000-0003

    Last Modified: 16 Apr 2026

    Buffer overflow in UnixWare rtpm program allows local users to gain privileges via a long environmental variable.

    Published: 30 Dec 1999
    7.5
    High

    CVE-2000-0043

    Last Modified: 16 Apr 2026

    Buffer overflow in CamShot WebCam HTTP server allows remote attackers to execute commands via a long GET request.

    Published: 30 Dec 1999
    2.1
    Low

    CVE-2000-0076

    Last Modified: 16 Apr 2026

    nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.

    Published: 30 Dec 1999
    5
    Medium

    CVE-1999-0001

    Last Modified: 16 Apr 2026

    ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.

    Published: 30 Dec 1999
    5
    Medium

    CVE-2000-0007

    Last Modified: 16 Apr 2026

    Trend Micro PC-Cillin does not restrict access to its internal proxy port, allowing remote attackers to conduct a denial of service.

    Published: 29 Dec 1999
    10
    Critical

    CVE-2000-0042

    Last Modified: 16 Apr 2026

    Buffer overflow in CSM mail server allows remote attackers to cause a denial of service or execute commands via a long HELO command.

    Published: 29 Dec 1999
    7.2
    High

    CVE-2000-0009

    Last Modified: 16 Apr 2026

    The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which allows local users to execute arbitrary commands.

    Published: 29 Dec 1999
    5
    Medium

    CVE-2000-0039

    Last Modified: 16 Apr 2026

    AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program.

    Published: 29 Dec 1999
    7.2
    High

    CVE-2000-0100

    Last Modified: 16 Apr 2026

    The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.

    Published: 29 Dec 1999
    10
    Critical

    CVE-1999-1573

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.

    Published: 28 Dec 1999
    5
    Medium

    CVE-2000-0014

    Last Modified: 16 Apr 2026

    Denial of service in Savant web server via a null character in the requested URL.

    Published: 28 Dec 1999
    5
    Medium

    CVE-2000-0041

    Last Modified: 16 Apr 2026

    Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.

    Published: 28 Dec 1999
    4.6
    Medium

    CVE-2000-0035

    Last Modified: 16 Apr 2026

    resend command in Majordomo allows local users to gain privileges via shell metacharacters.

    Published: 28 Dec 1999
    4.6
    Medium

    CVE-2000-0037

    Last Modified: 16 Apr 2026

    Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.

    Published: 28 Dec 1999
    6.2
    Medium

    CVE-2000-0027

    Last Modified: 16 Apr 2026

    IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.

    Published: 27 Dec 1999
    4.6
    Medium

    CVE-2000-0029

    Last Modified: 16 Apr 2026

    UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.

    Published: 27 Dec 1999
    5
    Medium

    CVE-2000-0033

    Last Modified: 16 Apr 2026

    InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.

    Published: 27 Dec 1999
    5
    Medium

    CVE-2000-0060

    Last Modified: 16 Apr 2026

    Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name.

    Published: 27 Dec 1999
    10
    Critical

    CVE-2000-0012

    Last Modified: 16 Apr 2026

    Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.

    Published: 27 Dec 1999
    2.1
    Low

    CVE-2000-0008

    Last Modified: 16 Apr 2026

    FTPPro allows local users to read sensitive information, which is stored in plain text.

    Published: 26 Dec 1999
    10
    Critical

    CVE-2000-0010

    Last Modified: 16 Apr 2026

    WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.

    Published: 26 Dec 1999
    7.5
    High

    CVE-1999-0477

    Last Modified: 16 Apr 2026

    The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.

    Published: 25 Dec 1999
    2.6
    Low

    CVE-2000-0006

    Last Modified: 16 Apr 2026

    strace allows local users to read arbitrary files via memory mapped file names.

    Published: 25 Dec 1999
    7.5
    High

    CVE-1999-0455

    Last Modified: 16 Apr 2026

    The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.

    Published: 25 Dec 1999
    4.6
    Medium

    CVE-1999-0892

    Last Modified: 16 Apr 2026

    Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.

    Published: 24 Dec 1999
    5
    Medium

    CVE-2000-0001

    Last Modified: 16 Apr 2026

    RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.

    Published: 23 Dec 1999
    2.6
    Low

    CVE-2000-0028

    Last Modified: 16 Apr 2026

    Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.

    Published: 23 Dec 1999
    7.5
    High

    CVE-2000-0038

    Last Modified: 16 Apr 2026

    glFtpD includes a default glftpd user account with a default password and a UID of 0.

    Published: 23 Dec 1999
    10
    Critical

    CVE-2000-0040

    Last Modified: 16 Apr 2026

    glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.

    Published: 23 Dec 1999
    5
    Medium

    CVE-1999-1109

    Last Modified: 16 Apr 2026

    Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.

    Published: 22 Dec 1999
    10
    Critical

    CVE-2000-0002

    Last Modified: 16 Apr 2026

    Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.

    Published: 22 Dec 1999
    7.2
    High

    CVE-2000-0018

    Last Modified: 16 Apr 2026

    wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.

    Published: 22 Dec 1999
    5
    Medium

    CVE-2000-0030

    Last Modified: 16 Apr 2026

    Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database.

    Published: 22 Dec 1999
    10
    Critical

    CVE-2000-0032

    Last Modified: 16 Apr 2026

    Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.

    Published: 22 Dec 1999
    5
    Medium

    CVE-2000-0034

    Last Modified: 16 Apr 2026

    Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."

    Published: 22 Dec 1999
    5
    Medium

    CVE-2000-0036

    Last Modified: 16 Apr 2026

    Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.

    Published: 22 Dec 1999
    7.2
    High

    CVE-2000-0119

    Last Modified: 16 Apr 2026

    The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection.

    Published: 22 Dec 1999
    5
    Medium

    CVE-1999-1066

    Last Modified: 16 Apr 2026

    Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.

    Published: 22 Dec 1999
    10
    Critical

    CVE-2000-0026

    Last Modified: 16 Apr 2026

    Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string.

    Published: 21 Dec 1999
    10
    Critical

    CVE-2000-0017

    Last Modified: 16 Apr 2026

    Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.

    Published: 21 Dec 1999
    5
    Medium

    CVE-2000-0022

    Last Modified: 16 Apr 2026

    Lotus Domino HTTP server does not properly disable anonymous access for the cgi-bin directory.

    Published: 21 Dec 1999
    5
    Medium

    CVE-2000-0023

    Last Modified: 16 Apr 2026

    Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL.

    Published: 21 Dec 1999
    6.4
    Medium

    CVE-2000-0024

    Last Modified: 16 Apr 2026

    IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.

    Published: 21 Dec 1999