CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-1999-1264

    Last Modified: 16 Apr 2026

    WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been explicitly disabled.

    Published: 21 Jan 1999
    7.2
    High

    CVE-1999-0121

    Last Modified: 16 Apr 2026

    Buffer overflow in dtaction command gives root access.

    Published: 21 Jan 1999
    2.1
    Low

    CVE-1999-0451

    Last Modified: 16 Apr 2026

    Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.

    Published: 19 Jan 1999
    10
    Critical

    CVE-1999-0119

    Last Modified: 16 Apr 2026

    Windows NT 4.0 beta allows users to read and delete shares.

    Published: 19 Jan 1999
    7.2
    High

    CVE-1999-0457

    Last Modified: 16 Apr 2026

    Linux ftpwatch program allows local users to gain root privileges.

    Published: 17 Jan 1999
    5
    Medium

    CVE-1999-0678

    Last Modified: 16 Apr 2026

    A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

    Published: 17 Jan 1999
    10
    Critical

    CVE-1999-1376

    Last Modified: 16 Apr 2026

    Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.

    Published: 14 Jan 1999
    2.1
    Low

    CVE-1999-1538

    Last Modified: 16 Apr 2026

    When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.

    Published: 14 Jan 1999
    5
    Medium

    CVE-1999-1172

    Last Modified: 16 Apr 2026

    By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.

    Published: 14 Jan 1999
    5
    Medium

    CVE-1999-0063

    Last Modified: 16 Apr 2026

    Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.

    Published: 11 Jan 1999
    5
    Medium

    CVE-1999-0392

    Last Modified: 16 Apr 2026

    Buffer overflow in Thomas Boutell's cgic library version up to 1.05.

    Published: 10 Jan 1999
    2.1
    Low

    CVE-1999-0442

    Last Modified: 16 Apr 2026

    Solaris ff.core allows local users to modify files.

    Published: 7 Jan 1999
    2.1
    Low

    CVE-1999-0458

    Last Modified: 16 Apr 2026

    L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.

    Published: 6 Jan 1999
    7.2
    High

    CVE-1999-1268

    Last Modified: 16 Apr 2026

    Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.

    Published: 6 Jan 1999
    7.5
    High

    CVE-1999-0391

    Last Modified: 16 Apr 2026

    The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.

    Published: 5 Jan 1999
    7.2
    High

    CVE-1999-0390

    Last Modified: 16 Apr 2026

    Buffer overflow in Dosemu Slang library in Linux.

    Published: 4 Jan 1999
    2.1
    Low

    CVE-1999-0464

    Last Modified: 16 Apr 2026

    Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.

    Published: 4 Jan 1999
    7.2
    High

    CVE-1999-0389

    Last Modified: 16 Apr 2026

    Buffer overflow in the bootp server in the Debian Linux netstd package.

    Published: 3 Jan 1999
    7.2
    High

    CVE-1999-0914

    Last Modified: 16 Apr 2026

    Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.

    Published: 3 Jan 1999
    5
    Medium

    CVE-2000-0054

    Last Modified: 16 Apr 2026

    search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack.

    Published: 3 Jan 1999
    7.2
    High

    CVE-2000-0005

    Last Modified: 16 Apr 2026

    HP-UX aserver program allows local users to gain privileges via a symlink attack.

    Published: 2 Jan 1999
    5
    Medium

    CVE-1999-0402

    Last Modified: 16 Apr 2026

    wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.

    Published: 2 Jan 1999
    7.2
    High

    CVE-1999-1422

    Last Modified: 16 Apr 2026

    The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.

    Published: 2 Jan 1999
    4.6
    Medium

    CVE-1999-1170

    Last Modified: 16 Apr 2026

    IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.

    Published: 2 Jan 1999
    7.3
    High

    CVE-1999-0632

    Last Modified: 28 May 2026

    The RPC portmapper service is running.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0530

    Last Modified: 16 Apr 2026

    A system is operating in "promiscuous" mode which allows it to perform packet sniffing.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0561

    Last Modified: 16 Apr 2026

    IIS has the #exec function enabled for Server Side Include (SSI) files.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0568

    Last Modified: 16 Apr 2026

    rpc.admind in Solaris is not running in a secure mode.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0642

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A POP service is running.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0285

    Last Modified: 16 Apr 2026

    Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0655

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is not about any specific product, protocol, or design, so it is out of scope of CVE. Notes: the former description is: "A service may include useful information in its banner or help function (such as the name and version), making it useful for information gathering activities.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0200

    Last Modified: 16 Apr 2026

    Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0564

    Last Modified: 16 Apr 2026

    An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0620

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A component service related to NIS is running.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0599

    Last Modified: 16 Apr 2026

    A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0571

    Last Modified: 16 Apr 2026

    A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0645

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The IRC service is running.

    Published: 1 Jan 1999
    5
    Medium

    CVE-1999-0656

    Last Modified: 16 Apr 2026

    The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0611

    Last Modified: 16 Apr 2026

    A system-critical Windows NT registry key has an inappropriate value.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0622

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A component service related to DNS service is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0020

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0032. Reason: This candidate is a duplicate of CVE-1999-0032. Notes: All CVE users should reference CVE-1999-0032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0110

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0315. Reason: This candidate's original description had a typo that delayed it from being detected as a duplicate of CVE-1999-0315. Notes: All CVE users should reference CVE-1999-0315 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0187

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0022. Reason: This candidate is a duplicate of CVE-1999-0022. Notes: All CVE users should reference CVE-1999-0022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0197

    Last Modified: 16 Apr 2026

    finger 0@host on some systems may print information on some user accounts.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0198

    Last Modified: 16 Apr 2026

    finger .@host on some systems may print information on some user accounts.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0220

    Last Modified: 16 Apr 2026

    Attackers can do a denial of service of IRC by crashing the server.

    Published: 1 Jan 1999
    7.5
    High

    CVE-1999-0240

    Last Modified: 16 Apr 2026

    Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0243

    Last Modified: 16 Apr 2026

    Linux cfingerd could be exploited to gain root access.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0255

    Last Modified: 16 Apr 2026

    Buffer overflow in ircd allows arbitrary command execution.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0268

    Last Modified: 16 Apr 2026

    MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.

    Published: 1 Jan 1999