CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2000-0073

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.

    Published: 17 Nov 1999
    7.8
    High

    CVE-1999-1549

    Last Modified: 16 Apr 2026

    Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.

    Published: 16 Nov 1999
    5
    Medium

    CVE-1999-1051

    Last Modified: 16 Apr 2026

    Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.

    Published: 16 Nov 1999
    7.5
    High

    CVE-1999-1457

    Last Modified: 16 Apr 2026

    Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.

    Published: 16 Nov 1999
    10
    Critical

    CVE-1999-1508

    Last Modified: 16 Apr 2026

    Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html.

    Published: 16 Nov 1999
    10
    Critical

    CVE-1999-1190

    Last Modified: 16 Apr 2026

    Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message.

    Published: 15 Nov 1999
    4.6
    Medium

    CVE-1999-1528

    Last Modified: 16 Apr 2026

    ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same system access to the unprotected NDS session.

    Published: 14 Nov 1999
    5
    Medium

    CVE-1999-1110

    Last Modified: 16 Apr 2026

    Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.

    Published: 14 Nov 1999
    7.5
    High

    CVE-2000-0165

    Last Modified: 16 Apr 2026

    The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands.

    Published: 13 Nov 1999
    7.6
    High

    CVE-2000-0330

    Last Modified: 16 Apr 2026

    The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.

    Published: 12 Nov 1999
    5
    Medium

    CVE-1999-1050

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.

    Published: 12 Nov 1999
    5.1
    Medium

    CVE-2000-0329

    Last Modified: 16 Apr 2026

    A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.

    Published: 11 Nov 1999
    7.5
    High

    CVE-1999-0833

    Last Modified: 16 Apr 2026

    Buffer overflow in BIND 8.2 via NXT records.

    Published: 10 Nov 1999
    10
    Critical

    CVE-1999-0835

    Last Modified: 16 Apr 2026

    Denial of service in BIND named via malformed SIG records.

    Published: 10 Nov 1999
    2.1
    Low

    CVE-1999-0851

    Last Modified: 16 Apr 2026

    Denial of service in BIND named via naptr.

    Published: 10 Nov 1999
    5
    Medium

    CVE-1999-0848

    Last Modified: 16 Apr 2026

    Denial of service in BIND named via consuming more than "fdmax" file descriptors.

    Published: 10 Nov 1999
    5
    Medium

    CVE-1999-0849

    Last Modified: 16 Apr 2026

    Denial of service in BIND named via maxdname.

    Published: 10 Nov 1999
    7.5
    High

    CVE-1999-1511

    Last Modified: 16 Apr 2026

    Buffer overflows in Xtramail 1.11 allow attackers to cause a denial of service (crash) and possibly execute arbitrary commands via (1) a long PASS command in the POP3 service, (2) a long HELO command in the SMTP service, or (3) a long user name in the Control Service.

    Published: 10 Nov 1999
    7.5
    High

    CVE-1999-1539

    Last Modified: 16 Apr 2026

    Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password.

    Published: 10 Nov 1999
    10
    Critical

    CVE-1999-0837

    Last Modified: 16 Apr 2026

    Denial of service in BIND by improperly closing TCP sessions via so_linger.

    Published: 10 Nov 1999
    7.5
    High

    CVE-1999-0983

    Last Modified: 16 Apr 2026

    Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.

    Published: 9 Nov 1999
    7.5
    High

    CVE-1999-0984

    Last Modified: 16 Apr 2026

    Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.

    Published: 9 Nov 1999
    10
    Critical

    CVE-1999-0832

    Last Modified: 16 Apr 2026

    Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.

    Published: 9 Nov 1999
    7.5
    High

    CVE-1999-1112

    Last Modified: 16 Apr 2026

    Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header.

    Published: 9 Nov 1999
    7.5
    High

    CVE-1999-1111

    Last Modified: 16 Apr 2026

    Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry itself.

    Published: 9 Nov 1999
    7.5
    High

    CVE-1999-0985

    Last Modified: 16 Apr 2026

    CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.

    Published: 9 Nov 1999
    9.8
    Critical

    CVE-1999-0199

    Last Modified: 20 Nov 2024

    manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.

    Published: 9 Nov 1999
    4.6
    Medium

    CVE-1999-0821

    Last Modified: 16 Apr 2026

    FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument.

    Published: 8 Nov 1999
    4.6
    Medium

    CVE-1999-0863

    Last Modified: 16 Apr 2026

    Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI.

    Published: 8 Nov 1999
    3.6
    Low

    CVE-1999-1530

    Last Modified: 16 Apr 2026

    cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.

    Published: 8 Nov 1999
    10
    Critical

    CVE-2001-0679

    Last Modified: 16 Apr 2026

    A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server.

    Published: 8 Nov 1999
    5
    Medium

    CVE-1999-1550

    Last Modified: 16 Apr 2026

    bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter.

    Published: 8 Nov 1999
    6.2
    Medium

    CVE-2000-0031

    Last Modified: 16 Apr 2026

    The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.

    Published: 8 Nov 1999
    7.5
    High

    CVE-1999-1533

    Last Modified: 16 Apr 2026

    Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file in its HTTP service.

    Published: 7 Nov 1999
    7.5
    High

    CVE-1999-1529

    Last Modified: 16 Apr 2026

    A buffer overflow exists in the HELO command in Trend Micro Interscan VirusWall SMTP gateway 3.23/3.3 for NT, which may allow an attacker to execute arbitrary code.

    Published: 7 Nov 1999
    5
    Medium

    CVE-1999-0843

    Last Modified: 16 Apr 2026

    Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port.

    Published: 4 Nov 1999
    10
    Critical

    CVE-1999-0896

    Last Modified: 16 Apr 2026

    Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.

    Published: 4 Nov 1999
    7.2
    High

    CVE-1999-1340

    Last Modified: 16 Apr 2026

    Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument.

    Published: 4 Nov 1999
    5
    Medium

    CVE-1999-1509

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL.

    Published: 4 Nov 1999
    5
    Medium

    CVE-1999-0887

    Last Modified: 16 Apr 2026

    FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.

    Published: 4 Nov 1999
    7.2
    High

    CVE-1999-0898

    Last Modified: 16 Apr 2026

    Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.

    Published: 4 Nov 1999
    7.5
    High

    CVE-1999-1065

    Last Modified: 16 Apr 2026

    Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.

    Published: 4 Nov 1999
    7.2
    High

    CVE-1999-1571

    Last Modified: 16 Apr 2026

    Buffer overflow in sar for SCO OpenServer 5.0.0 through 5.0.5 may allow local users to gain root privileges via a long -f parameter, a different vulnerability than CVE-1999-1570.

    Published: 4 Nov 1999
    7.2
    High

    CVE-1999-0899

    Last Modified: 16 Apr 2026

    The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.

    Published: 4 Nov 1999
    5
    Medium

    CVE-1999-0904

    Last Modified: 16 Apr 2026

    Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username.

    Published: 3 Nov 1999
    3.6
    Low

    CVE-1999-0885

    Last Modified: 16 Apr 2026

    Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL.

    Published: 3 Nov 1999
    7.5
    High

    CVE-1999-0947

    Last Modified: 16 Apr 2026

    AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell metacharacters.

    Published: 2 Nov 1999
    5.1
    Medium

    CVE-1999-0946

    Last Modified: 16 Apr 2026

    Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag.

    Published: 2 Nov 1999
    7.2
    High

    CVE-1999-0949

    Last Modified: 16 Apr 2026

    Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.

    Published: 2 Nov 1999
    7.2
    High

    CVE-1999-0948

    Last Modified: 16 Apr 2026

    Buffer overflow in uum program for Canna input system allows local users to gain root privileges.

    Published: 2 Nov 1999