CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-1999-0745

    Last Modified: 16 Apr 2026

    Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.

    Published: 18 Aug 1999
    7.5
    High

    CVE-1999-0753

    Last Modified: 16 Apr 2026

    The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.

    Published: 17 Aug 1999
    5
    Medium

    CVE-1999-0746

    Last Modified: 16 Apr 2026

    A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.

    Published: 16 Aug 1999
    2.6
    Low

    CVE-1999-0749

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.

    Published: 16 Aug 1999
    4.6
    Medium

    CVE-1999-0888

    Last Modified: 16 Apr 2026

    dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.

    Published: 16 Aug 1999
    7.5
    High

    CVE-1999-0679

    Last Modified: 16 Apr 2026

    Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.

    Published: 13 Aug 1999
    4.6
    Medium

    CVE-1999-0724

    Last Modified: 16 Apr 2026

    Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.

    Published: 12 Aug 1999
    5
    Medium

    CVE-1999-1336

    Last Modified: 16 Apr 2026

    3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port.

    Published: 12 Aug 1999
    5
    Medium

    CVE-1999-0867

    Last Modified: 16 Apr 2026

    Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.

    Published: 11 Aug 1999
    7.5
    High

    CVE-1999-0875

    Last Modified: 16 Apr 2026

    DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.

    Published: 11 Aug 1999
    2.6
    Low

    CVE-1999-0861

    Last Modified: 16 Apr 2026

    Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.

    Published: 11 Aug 1999
    2.1
    Low

    CVE-1999-0694

    Last Modified: 16 Apr 2026

    Denial of service in AIX ptrace system call allows local users to crash the system.

    Published: 11 Aug 1999
    10
    Critical

    CVE-1999-0814

    Last Modified: 16 Apr 2026

    Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.

    Published: 11 Aug 1999
    7.2
    High

    CVE-1999-0813

    Last Modified: 16 Apr 2026

    Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.

    Published: 10 Aug 1999
    5
    Medium

    CVE-1999-0680

    Last Modified: 16 Apr 2026

    Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.

    Published: 9 Aug 1999
    7.2
    High

    CVE-1999-0674

    Last Modified: 16 Apr 2026

    The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.

    Published: 9 Aug 1999
    5
    Medium

    CVE-1999-0675

    Last Modified: 16 Apr 2026

    Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.

    Published: 9 Aug 1999
    4.6
    Medium

    CVE-1999-0676

    Last Modified: 16 Apr 2026

    sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.

    Published: 9 Aug 1999
    10
    Critical

    CVE-1999-0722

    Last Modified: 16 Apr 2026

    The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.

    Published: 8 Aug 1999
    5.1
    Medium

    CVE-1999-0673

    Last Modified: 16 Apr 2026

    Buffer overflow in ALMail32 POP3 client via From: or To: headers.

    Published: 8 Aug 1999
    5
    Medium

    CVE-1999-1524

    Last Modified: 16 Apr 2026

    FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.

    Published: 7 Aug 1999
    5
    Medium

    CVE-1999-0682

    Last Modified: 16 Apr 2026

    Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.

    Published: 6 Aug 1999
    5
    Medium

    CVE-1999-0727

    Last Modified: 16 Apr 2026

    A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.

    Published: 6 Aug 1999
    10
    Critical

    CVE-1999-0913

    Last Modified: 16 Apr 2026

    dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.

    Published: 5 Aug 1999
    5.1
    Medium

    CVE-1999-0671

    Last Modified: 16 Apr 2026

    Buffer overflow in ToxSoft NextFTP client through CWD command.

    Published: 3 Aug 1999
    7.5
    High

    CVE-1999-0677

    Last Modified: 16 Apr 2026

    The WebRamp web administration utility has a default password.

    Published: 3 Aug 1999
    3.6
    Low

    CVE-1999-0703

    Last Modified: 16 Apr 2026

    OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.

    Published: 3 Aug 1999
    5.1
    Medium

    CVE-1999-0672

    Last Modified: 16 Apr 2026

    Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.

    Published: 1 Aug 1999
    4.6
    Medium

    CVE-1999-1337

    Last Modified: 16 Apr 2026

    FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.

    Published: 1 Aug 1999
    5
    Medium

    CVE-1999-0683

    Last Modified: 16 Apr 2026

    Denial of service in Gauntlet Firewall via a malformed ICMP packet.

    Published: 30 Jul 1999
    7.2
    High

    CVE-1999-1227

    Last Modified: 16 Apr 2026

    Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.

    Published: 30 Jul 1999
    7.2
    High

    CVE-1999-1536

    Last Modified: 16 Apr 2026

    .sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.

    Published: 30 Jul 1999
    5
    Medium

    CVE-1999-1130

    Last Modified: 16 Apr 2026

    Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.

    Published: 30 Jul 1999
    6.2
    Medium

    CVE-1999-0700

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.

    Published: 29 Jul 1999
    2.1
    Low

    CVE-1999-0770

    Last Modified: 16 Apr 2026

    Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.

    Published: 29 Jul 1999
    7.5
    High

    CVE-1999-1078

    Last Modified: 16 Apr 2026

    WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.

    Published: 29 Jul 1999
    7.6
    High

    CVE-2000-0323

    Last Modified: 16 Apr 2026

    The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.

    Published: 28 Jul 1999
    7.5
    High

    CVE-1999-1017

    Last Modified: 16 Apr 2026

    Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.

    Published: 28 Jul 1999
    7.5
    High

    CVE-1999-1018

    Last Modified: 16 Apr 2026

    IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.

    Published: 27 Jul 1999
    7.5
    High

    CVE-1999-0710

    Last Modified: 16 Apr 2026

    The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.

    Published: 25 Jul 1999
    5
    Medium

    CVE-1999-0224

    Last Modified: 16 Apr 2026

    Denial of service in Windows NT messenger service through a long username.

    Published: 23 Jul 1999
    4.6
    Medium

    CVE-1999-0719

    Last Modified: 16 Apr 2026

    The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.

    Published: 23 Jul 1999
    5
    Medium

    CVE-1999-1338

    Last Modified: 16 Apr 2026

    Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.

    Published: 21 Jul 1999
    7.2
    High

    CVE-1999-1165

    Last Modified: 16 Apr 2026

    GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.

    Published: 21 Jul 1999
    10
    Critical

    CVE-1999-0810

    Last Modified: 16 Apr 2026

    Denial of service in Samba NETBIOS name service daemon (nmbd).

    Published: 21 Jul 1999
    5
    Medium

    CVE-1999-0811

    Last Modified: 16 Apr 2026

    Buffer overflow in Samba smbd program via a malformed message command.

    Published: 21 Jul 1999
    10
    Critical

    CVE-1999-1535

    Last Modified: 16 Apr 2026

    Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request.

    Published: 20 Jul 1999
    7.2
    High

    CVE-1999-1560

    Last Modified: 16 Apr 2026

    Vulnerability in a script in Texas A&M University (TAMU) Tiger allows local users to execute arbitrary commands as the Tiger user, usually root.

    Published: 20 Jul 1999
    7.8
    High

    CVE-1999-0721

    Last Modified: 16 Apr 2026

    Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.

    Published: 20 Jul 1999
    5
    Medium

    CVE-1999-1378

    Last Modified: 16 Apr 2026

    dbmlparser.exe CGI guestbook program does not perform a chroot operation properly, which allows remote attackers to read arbitrary files.

    Published: 19 Jul 1999