CVE-1999-0578
Last Modified: 16 Apr 2026A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.
CVE-1999-0587
Last Modified: 16 Apr 2026A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.
CVE-1999-0593
Last Modified: 16 Apr 2026The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.
CVE-1999-0596
Last Modified: 16 Apr 2026A Windows NT log file has an inappropriate maximum size or retention period.
CVE-1999-0602
Last Modified: 16 Apr 2026A network intrusion detection system (IDS) does not properly reassemble fragmented packets.
CVE-1999-0618
Last Modified: 16 Apr 2026The rexec service is running.
CVE-1999-0630
Last Modified: 16 Apr 2026The NT Alerter and Messenger services are running.
CVE-1999-0641
Last Modified: 16 Apr 2026The UUCP service is running.
CVE-1999-0650
Last Modified: 16 Apr 2026The netstat service is running, which provides sensitive information to remote attackers.
CVE-1999-0657
Last Modified: 16 Apr 2026WinGate is being used.
CVE-1999-0663
Last Modified: 16 Apr 2026A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified.
CVE-1999-0665
Last Modified: 16 Apr 2026An application-critical Windows NT registry key has an inappropriate value.
CVE-1999-1440
Last Modified: 16 Apr 2026Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client.
CVE-1999-1568
Last Modified: 16 Apr 2026Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.
CVE-1999-0205
Last Modified: 16 Apr 2026Denial of service in Sendmail 8.6.11 and 8.6.12.
CVE-1999-0226
Last Modified: 16 Apr 2026Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
CVE-1999-0361
Last Modified: 16 Apr 2026NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.
CVE-1999-0393
Last Modified: 16 Apr 2026Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
CVE-1999-0520
Last Modified: 16 Apr 2026A system-critical NETBIOS/SMB share has inappropriate access control.
CVE-1999-0531
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "An SMTP service supports EXPN, VRFY, HELP, ESMTP, and/or EHLO.
CVE-1999-0565
Last Modified: 16 Apr 2026A Sendmail alias allows input to be piped to a program.
CVE-1999-0583
Last Modified: 16 Apr 2026There is a one-way or two-way trust relationship between Windows NT domains.
CVE-1999-0577
Last Modified: 16 Apr 2026A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
CVE-1999-0603
Last Modified: 16 Apr 2026In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc.
CVE-1999-0594
Last Modified: 16 Apr 2026A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.
CVE-1999-0600
Last Modified: 16 Apr 2026A network intrusion detection system (IDS) does not verify the checksum on a packet.
CVE-1999-0621
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A component service related to NETBIOS is running.
CVE-1999-0631
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The NFS service is running.
CVE-1999-0643
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The IMAP service is running.
CVE-1999-0644
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The NNTP news service is running.
CVE-1999-0661
Last Modified: 16 Apr 2026A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.
CVE-1999-0664
Last Modified: 16 Apr 2026An application-critical Windows NT registry key has inappropriate permissions.
CVE-1999-1430
Last Modified: 16 Apr 2026PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.
CVE-1999-0613
Last Modified: 16 Apr 2026The rpc.sprayd service is running.
CVE-1999-0286
Last Modified: 16 Apr 2026In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.
CVE-1999-0355
Last Modified: 16 Apr 2026Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.
CVE-1999-0394
Last Modified: 16 Apr 2026DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.
CVE-1999-0401
Last Modified: 16 Apr 2026A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.
CVE-1999-0495
Last Modified: 16 Apr 2026A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.
CVE-1999-0554
Last Modified: 16 Apr 2026NFS exports system-critical data to the world, e.g. / or a password file.
CVE-1999-0586
Last Modified: 16 Apr 2026A network service is running on a nonstandard port.
CVE-1999-0584
Last Modified: 16 Apr 2026A Windows NT file system is not NTFS.
CVE-1999-0601
Last Modified: 16 Apr 2026A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.
CVE-1999-1159
Last Modified: 16 Apr 2026SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.
CVE-1999-1285
Last Modified: 16 Apr 2026Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.
CVE-1999-1188
Last Modified: 16 Apr 2026mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.
CVE-1999-0968
Last Modified: 16 Apr 2026Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.
CVE-1999-1281
Last Modified: 16 Apr 2026Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.
CVE-1999-1278
Last Modified: 16 Apr 2026nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.
CVE-1999-1277
Last Modified: 16 Apr 2026BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.
