CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-1999-0364

    Last Modified: 16 Apr 2026

    Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.

    Published: 1 Jan 1999
    4.6
    Medium

    CVE-1999-0388

    Last Modified: 16 Apr 2026

    DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.

    Published: 1 Jan 1999
    4.6
    Medium

    CVE-1999-0398

    Last Modified: 16 Apr 2026

    In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0397

    Last Modified: 16 Apr 2026

    The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0452

    Last Modified: 16 Apr 2026

    A service or application has a backdoor password that was placed there by the developer.

    Published: 1 Jan 1999
    5
    Medium

    CVE-1999-0453

    Last Modified: 16 Apr 2026

    An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0454

    Last Modified: 16 Apr 2026

    A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0465

    Last Modified: 16 Apr 2026

    Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0497

    Last Modified: 16 Apr 2026

    Anonymous FTP is enabled.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0515

    Last Modified: 16 Apr 2026

    An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0512

    Last Modified: 16 Apr 2026

    A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0527

    Last Modified: 16 Apr 2026

    The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten.

    Published: 1 Jan 1999
    7.5
    High

    CVE-1999-0528

    Last Modified: 16 Apr 2026

    A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.

    Published: 1 Jan 1999
    7.5
    High

    CVE-1999-0529

    Last Modified: 16 Apr 2026

    A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0523

    Last Modified: 16 Apr 2026

    ICMP echo (ping) is allowed from arbitrary hosts.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0539

    Last Modified: 16 Apr 2026

    A trust relationship exists between two Unix hosts.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0555

    Last Modified: 16 Apr 2026

    A Unix account with a name other than "root" has UID 0, i.e. root privileges.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0556

    Last Modified: 16 Apr 2026

    Two or more Unix accounts have the same UID.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0559

    Last Modified: 16 Apr 2026

    A system-critical Unix file or directory has inappropriate permissions.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0548

    Last Modified: 16 Apr 2026

    A superfluous NFS server is running, but it is not importing or exporting any file systems.

    Published: 1 Jan 1999
    7.2
    High

    CVE-1999-0549

    Last Modified: 16 Apr 2026

    Windows NT automatically logs in an administrator upon rebooting.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0580

    Last Modified: 16 Apr 2026

    The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0581

    Last Modified: 16 Apr 2026

    The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0579

    Last Modified: 16 Apr 2026

    A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0589

    Last Modified: 16 Apr 2026

    A system-critical Windows NT registry key has inappropriate permissions.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0591

    Last Modified: 16 Apr 2026

    An event log in Windows NT has inappropriate access permissions.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0592

    Last Modified: 16 Apr 2026

    The Logon box of a Windows NT system displays the name of the last user who logged in.

    Published: 1 Jan 1999
    7.5
    High

    CVE-1999-0588

    Last Modified: 16 Apr 2026

    A filter in a router or firewall allows unusual fragmented packets.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0598

    Last Modified: 16 Apr 2026

    A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0597

    Last Modified: 16 Apr 2026

    A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0614

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The FTP service is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0615

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SNMP service is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0616

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The TFTP service is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0617

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SMTP service is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0619

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The Telnet service is running.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0625

    Last Modified: 16 Apr 2026

    The rpc.rquotad service is running.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0629

    Last Modified: 16 Apr 2026

    The ident/identd service is running.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0624

    Last Modified: 16 Apr 2026

    The rstat/rstatd service is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0623

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The X Windows service is running.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0636

    Last Modified: 16 Apr 2026

    The discard service is running.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0637

    Last Modified: 16 Apr 2026

    The systat service is running.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0638

    Last Modified: 16 Apr 2026

    The daytime service is running.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0639

    Last Modified: 16 Apr 2026

    The chargen service is running.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0640

    Last Modified: 16 Apr 2026

    The Gopher service is running.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0635

    Last Modified: 16 Apr 2026

    The echo service is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0633

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The HTTP/WWW service is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0634

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SSH service is running.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0654

    Last Modified: 16 Apr 2026

    The OS/2 or POSIX subsystem in NT is enabled.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0653

    Last Modified: 16 Apr 2026

    A component service related to NIS+ is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0646

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The LDAP service is running.

    Published: 1 Jan 1999