CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-1999-0578

    Last Modified: 16 Apr 2026

    A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0587

    Last Modified: 16 Apr 2026

    A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.

    Published: 1 Jan 1999
    4.9
    Medium

    CVE-1999-0593

    Last Modified: 16 Apr 2026

    The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0596

    Last Modified: 16 Apr 2026

    A Windows NT log file has an inappropriate maximum size or retention period.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0602

    Last Modified: 16 Apr 2026

    A network intrusion detection system (IDS) does not properly reassemble fragmented packets.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0618

    Last Modified: 16 Apr 2026

    The rexec service is running.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0630

    Last Modified: 16 Apr 2026

    The NT Alerter and Messenger services are running.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0641

    Last Modified: 16 Apr 2026

    The UUCP service is running.

    Published: 1 Jan 1999
    5
    Medium

    CVE-1999-0650

    Last Modified: 16 Apr 2026

    The netstat service is running, which provides sensitive information to remote attackers.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0657

    Last Modified: 16 Apr 2026

    WinGate is being used.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0663

    Last Modified: 16 Apr 2026

    A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0665

    Last Modified: 16 Apr 2026

    An application-critical Windows NT registry key has an inappropriate value.

    Published: 1 Jan 1999
    5.1
    Medium

    CVE-1999-1440

    Last Modified: 16 Apr 2026

    Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client.

    Published: 1 Jan 1999
    7.5
    High

    CVE-1999-1568

    Last Modified: 16 Apr 2026

    Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.

    Published: 1 Jan 1999
    5
    Medium

    CVE-1999-0205

    Last Modified: 16 Apr 2026

    Denial of service in Sendmail 8.6.11 and 8.6.12.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0226

    Last Modified: 16 Apr 2026

    Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0361

    Last Modified: 16 Apr 2026

    NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.

    Published: 1 Jan 1999
    5
    Medium

    CVE-1999-0393

    Last Modified: 16 Apr 2026

    Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.

    Published: 1 Jan 1999
    6.4
    Medium

    CVE-1999-0520

    Last Modified: 16 Apr 2026

    A system-critical NETBIOS/SMB share has inappropriate access control.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0531

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "An SMTP service supports EXPN, VRFY, HELP, ESMTP, and/or EHLO.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0565

    Last Modified: 16 Apr 2026

    A Sendmail alias allows input to be piped to a program.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0583

    Last Modified: 16 Apr 2026

    There is a one-way or two-way trust relationship between Windows NT domains.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0577

    Last Modified: 16 Apr 2026

    A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0603

    Last Modified: 16 Apr 2026

    In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0594

    Last Modified: 16 Apr 2026

    A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0600

    Last Modified: 16 Apr 2026

    A network intrusion detection system (IDS) does not verify the checksum on a packet.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0621

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A component service related to NETBIOS is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0631

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The NFS service is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0643

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The IMAP service is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0644

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The NNTP news service is running.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0661

    Last Modified: 16 Apr 2026

    A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0664

    Last Modified: 16 Apr 2026

    An application-critical Windows NT registry key has inappropriate permissions.

    Published: 1 Jan 1999
    2.1
    Low

    CVE-1999-1430

    Last Modified: 16 Apr 2026

    PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0613

    Last Modified: 16 Apr 2026

    The rpc.sprayd service is running.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0286

    Last Modified: 16 Apr 2026

    In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.

    Published: 1 Jan 1999
    5
    Medium

    CVE-1999-0355

    Last Modified: 16 Apr 2026

    Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0394

    Last Modified: 16 Apr 2026

    DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.

    Published: 1 Jan 1999
    3.7
    Low

    CVE-1999-0401

    Last Modified: 16 Apr 2026

    A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0495

    Last Modified: 16 Apr 2026

    A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0554

    Last Modified: 16 Apr 2026

    NFS exports system-critical data to the world, e.g. / or a password file.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0586

    Last Modified: 16 Apr 2026

    A network service is running on a nonstandard port.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0584

    Last Modified: 16 Apr 2026

    A Windows NT file system is not NTFS.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0601

    Last Modified: 16 Apr 2026

    A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.

    Published: 1 Jan 1999
    4.6
    Medium

    CVE-1999-1159

    Last Modified: 16 Apr 2026

    SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.

    Published: 29 Dec 1998
    2.1
    Low

    CVE-1999-1285

    Last Modified: 16 Apr 2026

    Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.

    Published: 27 Dec 1998
    4.6
    Medium

    CVE-1999-1188

    Last Modified: 16 Apr 2026

    mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.

    Published: 27 Dec 1998
    7.5
    High

    CVE-1999-0968

    Last Modified: 16 Apr 2026

    Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.

    Published: 26 Dec 1998
    5
    Medium

    CVE-1999-1281

    Last Modified: 16 Apr 2026

    Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.

    Published: 26 Dec 1998
    7.5
    High

    CVE-1999-1278

    Last Modified: 16 Apr 2026

    nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.

    Published: 25 Dec 1998
    4.6
    Medium

    CVE-1999-1277

    Last Modified: 16 Apr 2026

    BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.

    Published: 24 Dec 1998