CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-1999-1575

    Last Modified: 16 Apr 2026

    The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active Setup (setupctl.dll) ActiveX controls for Internet Explorer (IE) 4.01 and 5.0 are marked as "Safe for Scripting," which allows remote attackers to create and modify files and execute arbitrary commands.

    Published: 10 Sept 1999
    10
    Critical

    CVE-1999-0702

    Last Modified: 16 Apr 2026

    Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.

    Published: 10 Sept 1999
    5
    Medium

    CVE-1999-0910

    Last Modified: 16 Apr 2026

    Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.

    Published: 10 Sept 1999
    5
    Medium

    CVE-1999-1377

    Last Modified: 16 Apr 2026

    Matt Wright's download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

    Published: 9 Sept 1999
    7.2
    High

    CVE-1999-0697

    Last Modified: 16 Apr 2026

    SCO Doctor allows local users to gain root privileges through a Tools option.

    Published: 9 Sept 1999
    7.2
    High

    CVE-1999-0767

    Last Modified: 16 Apr 2026

    Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.

    Published: 8 Sept 1999
    4.6
    Medium

    CVE-1999-1353

    Last Modified: 16 Apr 2026

    Nosque MsgCore 2.14 stores passwords in cleartext: (1) the administrator password in the AdmPasswd registry key, and (2) user passwords in the Userbase.dbf data file, which could allow local users to gain privileges.

    Published: 7 Sept 1999
    2.1
    Low

    CVE-2000-0489

    Last Modified: 16 Apr 2026

    FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers.

    Published: 5 Sept 1999
    4.6
    Medium

    CVE-1999-1562

    Last Modified: 16 Apr 2026

    gFTP FTP client 1.13, and other versions before 2.0.0, records a password in plaintext in (1) the log window, or (2) in a log file.

    Published: 5 Sept 1999
    10
    Critical

    CVE-1999-0926

    Last Modified: 16 Apr 2026

    Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.

    Published: 3 Sept 1999
    5
    Medium

    CVE-1999-0925

    Last Modified: 16 Apr 2026

    UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers.

    Published: 3 Sept 1999
    2.1
    Low

    CVE-1999-1564

    Last Modified: 16 Apr 2026

    FreeBSD 3.2 and possibly other versions allows a local user to cause a denial of service (panic) with a large number accesses of an NFS v3 mounted directory from a large number of processes.

    Published: 2 Sept 1999
    5.1
    Medium

    CVE-1999-0685

    Last Modified: 16 Apr 2026

    Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.

    Published: 2 Sept 1999
    4.6
    Medium

    CVE-1999-1356

    Last Modified: 16 Apr 2026

    Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy.

    Published: 2 Sept 1999
    7.5
    High

    CVE-1999-1516

    Last Modified: 16 Apr 2026

    A buffer overflow in TenFour TFS Gateway SMTP mail server 3.2 allows an attacker to crash the mail server and possibly execute arbitrary code by offering more than 128 bytes in a MAIL FROM string.

    Published: 2 Sept 1999
    7.5
    High

    CVE-1999-1129

    Last Modified: 16 Apr 2026

    Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag.

    Published: 1 Sept 1999
    4
    Medium

    CVE-1999-0669

    Last Modified: 16 Apr 2026

    The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.

    Published: 1 Sept 1999
    4
    Medium

    CVE-1999-0670

    Last Modified: 16 Apr 2026

    Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.

    Published: 1 Sept 1999
    7.5
    High

    CVE-1999-0705

    Last Modified: 16 Apr 2026

    Buffer overflow in INN inews program.

    Published: 1 Sept 1999
    5
    Medium

    CVE-1999-0891

    Last Modified: 16 Apr 2026

    The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.

    Published: 1 Sept 1999
    7.2
    High

    CVE-1999-0774

    Last Modified: 16 Apr 2026

    Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.

    Published: 31 Aug 1999
    5
    Medium

    CVE-1999-1515

    Last Modified: 16 Apr 2026

    A non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender and recipient addresses, which causes the gateway to continuously try to return the message every 10 seconds.

    Published: 31 Aug 1999
    7.5
    High

    CVE-1999-1513

    Last Modified: 16 Apr 2026

    Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string, but lists the entire table of community strings, which could allow attackers to conduct unauthorized activities.

    Published: 30 Aug 1999
    4.6
    Medium

    CVE-1999-1354

    Last Modified: 16 Apr 2026

    E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled.

    Published: 30 Aug 1999
    10
    Critical

    CVE-1999-0911

    Last Modified: 16 Apr 2026

    Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.

    Published: 27 Aug 1999
    5
    Medium

    CVE-1999-1016

    Last Modified: 16 Apr 2026

    Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.

    Published: 27 Aug 1999
    5
    Medium

    CVE-1999-0939

    Last Modified: 16 Apr 2026

    Denial of service in Debian IRC Epic/epic4 client via a long string.

    Published: 26 Aug 1999
    4.6
    Medium

    CVE-1999-1235

    Last Modified: 16 Apr 2026

    Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.

    Published: 25 Aug 1999
    7.2
    High

    CVE-1999-0872

    Last Modified: 16 Apr 2026

    Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.

    Published: 25 Aug 1999
    7.5
    High

    CVE-1999-0768

    Last Modified: 16 Apr 2026

    Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.

    Published: 25 Aug 1999
    7.2
    High

    CVE-1999-0769

    Last Modified: 16 Apr 2026

    Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.

    Published: 25 Aug 1999
    5
    Medium

    CVE-2000-0328

    Last Modified: 16 Apr 2026

    Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.

    Published: 24 Aug 1999
    5
    Medium

    CVE-1999-1052

    Last Modified: 16 Apr 2026

    Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.

    Published: 24 Aug 1999
    4.6
    Medium

    CVE-1999-0720

    Last Modified: 16 Apr 2026

    The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.

    Published: 23 Aug 1999
    10
    Critical

    CVE-1999-0878

    Last Modified: 16 Apr 2026

    Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.

    Published: 22 Aug 1999
    10
    Critical

    CVE-2000-0374

    Last Modified: 16 Apr 2026

    The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions.

    Published: 22 Aug 1999
    10
    Critical

    CVE-1999-1064

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]).

    Published: 22 Aug 1999
    5.1
    Medium

    CVE-1999-0668

    Last Modified: 16 Apr 2026

    The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.

    Published: 21 Aug 1999
    7.5
    High

    CVE-2000-0355

    Last Modified: 16 Apr 2026

    pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.

    Published: 21 Aug 1999
    5
    Medium

    CVE-2000-1206

    Last Modified: 16 Apr 2026

    Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.

    Published: 20 Aug 1999
    4.6
    Medium

    CVE-1999-1565

    Last Modified: 16 Apr 2026

    Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

    Published: 20 Aug 1999
    2.1
    Low

    CVE-1999-0743

    Last Modified: 16 Apr 2026

    Trn allows local users to overwrite other users' files via symlinks.

    Published: 20 Aug 1999
    7.2
    High

    CVE-1999-1561

    Last Modified: 16 Apr 2026

    Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.

    Published: 20 Aug 1999
    7.2
    High

    CVE-2000-0325

    Last Modified: 16 Apr 2026

    The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.

    Published: 20 Aug 1999
    2.1
    Low

    CVE-1999-0732

    Last Modified: 16 Apr 2026

    The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.

    Published: 19 Aug 1999
    7.5
    High

    CVE-1999-0734

    Last Modified: 16 Apr 2026

    A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.

    Published: 19 Aug 1999
    6.4
    Medium

    CVE-1999-0740

    Last Modified: 16 Apr 2026

    Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.

    Published: 19 Aug 1999
    10
    Critical

    CVE-1999-0741

    Last Modified: 16 Apr 2026

    QMS CrownNet Unix Utilities for 2060 allows root to log on without a password.

    Published: 19 Aug 1999
    7.1
    High

    CVE-1999-0725

    Last Modified: 16 Apr 2026

    When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".

    Published: 19 Aug 1999
    2.1
    Low

    CVE-1999-0747

    Last Modified: 16 Apr 2026

    Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load.

    Published: 18 Aug 1999