CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2000-0025

    Last Modified: 16 Apr 2026

    IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.

    Published: 21 Dec 1999
    7.2
    High

    CVE-1999-1497

    Last Modified: 16 Apr 2026

    Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail accounts.

    Published: 21 Dec 1999
    7.5
    High

    CVE-1999-0997

    Last Modified: 16 Apr 2026

    wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.

    Published: 20 Dec 1999
    5
    Medium

    CVE-2000-0020

    Last Modified: 16 Apr 2026

    DNS PRO allows remote attackers to conduct a denial of service via a large number of connections.

    Published: 20 Dec 1999
    5
    Medium

    CVE-1999-1005

    Last Modified: 16 Apr 2026

    Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.

    Published: 19 Dec 1999
    5
    Medium

    CVE-1999-1006

    Last Modified: 16 Apr 2026

    Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.

    Published: 19 Dec 1999
    7.8
    High

    CVE-1999-0995

    Last Modified: 16 Apr 2026

    Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request."

    Published: 16 Dec 1999
    5
    Medium

    CVE-1999-0998

    Last Modified: 16 Apr 2026

    Cisco Cache Engine allows an attacker to replace content in the cache.

    Published: 16 Dec 1999
    5
    Medium

    CVE-1999-0994

    Last Modified: 16 Apr 2026

    Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.

    Published: 16 Dec 1999
    5
    Medium

    CVE-1999-1004

    Last Modified: 16 Apr 2026

    Buffer overflow in the POP server POProxy for the Norton Anti-Virus protection NAV2000 program via a large USER command.

    Published: 16 Dec 1999
    5
    Medium

    CVE-1999-1000

    Last Modified: 16 Apr 2026

    The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.

    Published: 16 Dec 1999
    2.6
    Low

    CVE-1999-1001

    Last Modified: 16 Apr 2026

    Cisco Cache Engine allows a remote attacker to gain access via a null username and password.

    Published: 16 Dec 1999
    10
    Critical

    CVE-1999-0935

    Last Modified: 16 Apr 2026

    classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.

    Published: 15 Dec 1999
    7.5
    High

    CVE-1999-0996

    Last Modified: 16 Apr 2026

    Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request.

    Published: 15 Dec 1999
    5
    Medium

    CVE-1999-0934

    Last Modified: 16 Apr 2026

    classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.

    Published: 15 Dec 1999
    2.1
    Low

    CVE-1999-1010

    Last Modified: 16 Apr 2026

    An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.

    Published: 14 Dec 1999
    7.5
    High

    CVE-2000-0068

    Last Modified: 16 Apr 2026

    daynad program in Intel InBusiness E-mail Station does not require authentication, which allows remote attackers to modify its configuration, delete files, or read mail.

    Published: 14 Dec 1999
    2.1
    Low

    CVE-2000-0361

    Last Modified: 16 Apr 2026

    The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.

    Published: 14 Dec 1999
    7.5
    High

    CVE-1999-0993

    Last Modified: 16 Apr 2026

    Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.

    Published: 13 Dec 1999
    7.6
    High

    CVE-1999-1007

    Last Modified: 16 Apr 2026

    Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.

    Published: 13 Dec 1999
    5
    Medium

    CVE-1999-1003

    Last Modified: 16 Apr 2026

    War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.

    Published: 13 Dec 1999
    2.6
    Low

    CVE-1999-1009

    Last Modified: 16 Apr 2026

    The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system.

    Published: 12 Dec 1999
    4.6
    Medium

    CVE-1999-0975

    Last Modified: 16 Apr 2026

    The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.

    Published: 10 Dec 1999
    10
    Critical

    CVE-1999-0977

    Last Modified: 16 Apr 2026

    Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.

    Published: 10 Dec 1999
    7.5
    High

    CVE-1999-0972

    Last Modified: 16 Apr 2026

    Buffer overflow in Xshipwars xsw program.

    Published: 9 Dec 1999
    10
    Critical

    CVE-1999-0974

    Last Modified: 16 Apr 2026

    Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.

    Published: 9 Dec 1999
    7.5
    High

    CVE-1999-0978

    Last Modified: 16 Apr 2026

    htdig allows remote attackers to execute commands via filenames with shell metacharacters.

    Published: 9 Dec 1999
    5.1
    Medium

    CVE-1999-0981

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."

    Published: 8 Dec 1999
    5
    Medium

    CVE-1999-0986

    Last Modified: 16 Apr 2026

    The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.

    Published: 8 Dec 1999
    10
    Critical

    CVE-1999-0973

    Last Modified: 16 Apr 2026

    Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.

    Published: 7 Dec 1999
    2.1
    Low

    CVE-1999-0976

    Last Modified: 16 Apr 2026

    Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.

    Published: 7 Dec 1999
    7.5
    High

    CVE-1999-0989

    Last Modified: 16 Apr 2026

    Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.

    Published: 6 Dec 1999
    5
    Medium

    CVE-1999-0991

    Last Modified: 16 Apr 2026

    Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name.

    Published: 6 Dec 1999
    7.2
    High

    CVE-1999-0982

    Last Modified: 16 Apr 2026

    The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.

    Published: 5 Dec 1999
    2.1
    Low

    CVE-1999-0990

    Last Modified: 16 Apr 2026

    Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.

    Published: 5 Dec 1999
    7.2
    High

    CVE-1999-0988

    Last Modified: 16 Apr 2026

    UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.

    Published: 4 Dec 1999
    7.2
    High

    CVE-1999-0866

    Last Modified: 16 Apr 2026

    Buffer overflow in UnixWare xauto program allows local users to gain root privilege.

    Published: 3 Dec 1999
    3.6
    Low

    CVE-1999-0825

    Last Modified: 16 Apr 2026

    The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.

    Published: 3 Dec 1999
    5
    Medium

    CVE-1999-0865

    Last Modified: 16 Apr 2026

    Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.

    Published: 3 Dec 1999
    7.2
    High

    CVE-1999-0864

    Last Modified: 16 Apr 2026

    UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.

    Published: 3 Dec 1999
    5
    Medium

    CVE-2000-0358

    Last Modified: 16 Apr 2026

    ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.

    Published: 3 Dec 1999
    2.1
    Low

    CVE-2000-0139

    Last Modified: 16 Apr 2026

    Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.

    Published: 3 Dec 1999
    7.5
    High

    CVE-2000-0357

    Last Modified: 16 Apr 2026

    ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.

    Published: 3 Dec 1999
    3.6
    Low

    CVE-1999-0850

    Last Modified: 16 Apr 2026

    The default permissions for Endymion MailMan allow local users to read email or modify files.

    Published: 2 Dec 1999
    7.2
    High

    CVE-1999-0852

    Last Modified: 16 Apr 2026

    IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.

    Published: 2 Dec 1999
    2.1
    Low

    CVE-1999-0862

    Last Modified: 16 Apr 2026

    Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.

    Published: 2 Dec 1999
    2.1
    Low

    CVE-2000-0366

    Last Modified: 16 Apr 2026

    dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.

    Published: 2 Dec 1999
    3.6
    Low

    CVE-1999-0828

    Last Modified: 16 Apr 2026

    UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.

    Published: 2 Dec 1999
    5
    Medium

    CVE-1999-0858

    Last Modified: 16 Apr 2026

    Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.

    Published: 2 Dec 1999
    4.6
    Medium

    CVE-1999-0823

    Last Modified: 16 Apr 2026

    Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.

    Published: 1 Dec 1999