CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-1999-0405

    Last Modified: 16 Apr 2026

    A buffer overflow in lsof allows local users to obtain root privilege.

    Published: 18 Feb 1999
    2.1
    Low

    CVE-1999-1495

    Last Modified: 16 Apr 2026

    xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.

    Published: 18 Feb 1999
    7.2
    High

    CVE-2000-0367

    Last Modified: 16 Apr 2026

    Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.

    Published: 18 Feb 1999
    10
    Critical

    CVE-1999-1405

    Last Modified: 16 Apr 2026

    snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

    Published: 17 Feb 1999
    2.6
    Low

    CVE-1999-0396

    Last Modified: 16 Apr 2026

    A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.

    Published: 17 Feb 1999
    5
    Medium

    CVE-1999-1060

    Last Modified: 16 Apr 2026

    Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.

    Published: 17 Feb 1999
    2.1
    Low

    CVE-1999-0374

    Last Modified: 16 Apr 2026

    Debian GNU/Linux cfengine package is susceptible to a symlink attack.

    Published: 16 Feb 1999
    7.5
    High

    CVE-1999-0375

    Last Modified: 16 Apr 2026

    Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.

    Published: 16 Feb 1999
    5
    Medium

    CVE-1999-1180

    Last Modified: 16 Apr 2026

    O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat.

    Published: 16 Feb 1999
    2.1
    Low

    CVE-1999-0714

    Last Modified: 16 Apr 2026

    Vulnerability in Compaq Tru64 UNIX edauth command.

    Published: 15 Feb 1999
    7.5
    High

    CVE-1999-1260

    Last Modified: 16 Apr 2026

    mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.

    Published: 15 Feb 1999
    7.5
    High

    CVE-1999-0404

    Last Modified: 16 Apr 2026

    Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.

    Published: 14 Feb 1999
    2.1
    Low

    CVE-1999-0372

    Last Modified: 16 Apr 2026

    The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.

    Published: 12 Feb 1999
    5
    Medium

    CVE-1999-1203

    Last Modified: 16 Apr 2026

    Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.

    Published: 12 Feb 1999
    1.2
    Low

    CVE-1999-0371

    Last Modified: 16 Apr 2026

    Lynx allows a local user to overwrite sensitive files through /tmp symlinks.

    Published: 11 Feb 1999
    5
    Medium

    CVE-1999-1375

    Last Modified: 16 Apr 2026

    FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.

    Published: 11 Feb 1999
    4.6
    Medium

    CVE-1999-0370

    Last Modified: 16 Apr 2026

    In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.

    Published: 10 Feb 1999
    9.3
    Critical

    CVE-1999-0353

    Last Modified: 16 Apr 2026

    rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.

    Published: 10 Feb 1999
    10
    Critical

    CVE-1999-0407

    Last Modified: 16 Apr 2026

    By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.

    Published: 9 Feb 1999
    2.1
    Low

    CVE-1999-0367

    Last Modified: 16 Apr 2026

    NetBSD netstat command allows local users to access kernel memory.

    Published: 9 Feb 1999
    10
    Critical

    CVE-1999-0368

    Last Modified: 16 Apr 2026

    Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.

    Published: 9 Feb 1999
    6.2
    Medium

    CVE-1999-0350

    Last Modified: 16 Apr 2026

    Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.

    Published: 8 Feb 1999
    7.5
    High

    CVE-1999-0366

    Last Modified: 16 Apr 2026

    In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.

    Published: 8 Feb 1999
    5
    Medium

    CVE-1999-1201

    Last Modified: 16 Apr 2026

    Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.

    Published: 6 Feb 1999
    7.5
    High

    CVE-1999-0365

    Last Modified: 16 Apr 2026

    The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.

    Published: 4 Feb 1999
    5
    Medium

    CVE-1999-1169

    Last Modified: 16 Apr 2026

    nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets.

    Published: 4 Feb 1999
    7.5
    High

    CVE-1999-0383

    Last Modified: 16 Apr 2026

    ACC Tigris allows public access without a login.

    Published: 2 Feb 1999
    5
    Medium

    CVE-1999-0362

    Last Modified: 16 Apr 2026

    WS_FTP server remote denial of service through cwd command.

    Published: 2 Feb 1999
    7.2
    High

    CVE-1999-0363

    Last Modified: 16 Apr 2026

    SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.

    Published: 2 Feb 1999
    2.6
    Low

    CVE-1999-1453

    Last Modified: 16 Apr 2026

    Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.

    Published: 2 Feb 1999
    4.6
    Medium

    CVE-1999-1171

    Last Modified: 16 Apr 2026

    IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.

    Published: 2 Feb 1999
    7.5
    High

    CVE-1999-0291

    Last Modified: 16 Apr 2026

    The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.

    Published: 1 Feb 1999
    6.4
    Medium

    CVE-1999-0351

    Last Modified: 16 Apr 2026

    FTP PASV "Pizza Thief" denial of service and unauthorized data access. Attackers can steal data by connecting to a port that was intended for use by a client.

    Published: 1 Feb 1999
    7.2
    High

    CVE-1999-0358

    Last Modified: 16 Apr 2026

    Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.

    Published: 1 Feb 1999
    4.6
    Medium

    CVE-1999-0459

    Last Modified: 16 Apr 2026

    Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.

    Published: 1 Feb 1999
    7.2
    High

    CVE-1999-0373

    Last Modified: 16 Apr 2026

    Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.

    Published: 1 Feb 1999
    5
    Medium

    CVE-1999-0403

    Last Modified: 16 Apr 2026

    A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.

    Published: 1 Feb 1999
    7.2
    High

    CVE-1999-0360

    Last Modified: 16 Apr 2026

    MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.

    Published: 30 Jan 1999
    5
    Medium

    CVE-1999-1546

    Last Modified: 16 Apr 2026

    netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.

    Published: 29 Jan 1999
    10
    Critical

    CVE-2000-0370

    Last Modified: 16 Apr 2026

    The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.

    Published: 29 Jan 1999
    10
    Critical

    CVE-1999-0461

    Last Modified: 16 Apr 2026

    Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.

    Published: 28 Jan 1999
    7.2
    High

    CVE-1999-0952

    Last Modified: 16 Apr 2026

    Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.

    Published: 28 Jan 1999
    7.5
    High

    CVE-1999-0349

    Last Modified: 16 Apr 2026

    A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.

    Published: 27 Jan 1999
    5
    Medium

    CVE-1999-0348

    Last Modified: 16 Apr 2026

    IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.

    Published: 27 Jan 1999
    7.5
    High

    CVE-1999-1450

    Last Modified: 16 Apr 2026

    Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges.

    Published: 27 Jan 1999
    4.6
    Medium

    CVE-1999-0400

    Last Modified: 16 Apr 2026

    Denial of service in Linux 2.2.0 running the ldd command on a core file.

    Published: 26 Jan 1999
    7.5
    High

    CVE-1999-0450

    Last Modified: 16 Apr 2026

    In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).

    Published: 26 Jan 1999
    10
    Critical

    CVE-1999-0347

    Last Modified: 16 Apr 2026

    Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.

    Published: 26 Jan 1999
    7.8
    High

    CVE-1999-0449

    Last Modified: 16 Apr 2026

    The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.

    Published: 26 Jan 1999
    10
    Critical

    CVE-1999-0356

    Last Modified: 16 Apr 2026

    ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.

    Published: 25 Jan 1999