CVE-1999-0364
Last Modified: 16 Apr 2026Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
CVE-1999-0388
Last Modified: 16 Apr 2026DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.
CVE-1999-0398
Last Modified: 16 Apr 2026In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.
CVE-1999-0397
Last Modified: 16 Apr 2026The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
CVE-1999-0452
Last Modified: 16 Apr 2026A service or application has a backdoor password that was placed there by the developer.
CVE-1999-0453
Last Modified: 16 Apr 2026An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).
CVE-1999-0454
Last Modified: 16 Apr 2026A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.
CVE-1999-0465
Last Modified: 16 Apr 2026Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
CVE-1999-0497
Last Modified: 16 Apr 2026Anonymous FTP is enabled.
CVE-1999-0515
Last Modified: 16 Apr 2026An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.
CVE-1999-0512
Last Modified: 16 Apr 2026A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
CVE-1999-0527
Last Modified: 16 Apr 2026The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten.
CVE-1999-0528
Last Modified: 16 Apr 2026A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.
CVE-1999-0529
Last Modified: 16 Apr 2026A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.
CVE-1999-0523
Last Modified: 16 Apr 2026ICMP echo (ping) is allowed from arbitrary hosts.
CVE-1999-0539
Last Modified: 16 Apr 2026A trust relationship exists between two Unix hosts.
CVE-1999-0555
Last Modified: 16 Apr 2026A Unix account with a name other than "root" has UID 0, i.e. root privileges.
CVE-1999-0556
Last Modified: 16 Apr 2026Two or more Unix accounts have the same UID.
CVE-1999-0559
Last Modified: 16 Apr 2026A system-critical Unix file or directory has inappropriate permissions.
CVE-1999-0548
Last Modified: 16 Apr 2026A superfluous NFS server is running, but it is not importing or exporting any file systems.
CVE-1999-0549
Last Modified: 16 Apr 2026Windows NT automatically logs in an administrator upon rebooting.
CVE-1999-0580
Last Modified: 16 Apr 2026The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.
CVE-1999-0581
Last Modified: 16 Apr 2026The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.
CVE-1999-0579
Last Modified: 16 Apr 2026A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
CVE-1999-0589
Last Modified: 16 Apr 2026A system-critical Windows NT registry key has inappropriate permissions.
CVE-1999-0591
Last Modified: 16 Apr 2026An event log in Windows NT has inappropriate access permissions.
CVE-1999-0592
Last Modified: 16 Apr 2026The Logon box of a Windows NT system displays the name of the last user who logged in.
CVE-1999-0588
Last Modified: 16 Apr 2026A filter in a router or firewall allows unusual fragmented packets.
CVE-1999-0598
Last Modified: 16 Apr 2026A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.
CVE-1999-0597
Last Modified: 16 Apr 2026A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.
CVE-1999-0614
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The FTP service is running.
CVE-1999-0615
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SNMP service is running.
CVE-1999-0616
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The TFTP service is running.
CVE-1999-0617
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SMTP service is running.
CVE-1999-0619
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The Telnet service is running.
CVE-1999-0625
Last Modified: 16 Apr 2026The rpc.rquotad service is running.
CVE-1999-0629
Last Modified: 16 Apr 2026The ident/identd service is running.
CVE-1999-0624
Last Modified: 16 Apr 2026The rstat/rstatd service is running.
CVE-1999-0623
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The X Windows service is running.
CVE-1999-0636
Last Modified: 16 Apr 2026The discard service is running.
CVE-1999-0637
Last Modified: 16 Apr 2026The systat service is running.
CVE-1999-0638
Last Modified: 16 Apr 2026The daytime service is running.
CVE-1999-0639
Last Modified: 16 Apr 2026The chargen service is running.
CVE-1999-0640
Last Modified: 16 Apr 2026The Gopher service is running.
CVE-1999-0635
Last Modified: 16 Apr 2026The echo service is running.
CVE-1999-0633
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The HTTP/WWW service is running.
CVE-1999-0634
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SSH service is running.
CVE-1999-0654
Last Modified: 16 Apr 2026The OS/2 or POSIX subsystem in NT is enabled.
CVE-1999-0653
Last Modified: 16 Apr 2026A component service related to NIS+ is running.
CVE-1999-0646
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The LDAP service is running.
