CVE Feed

    Dashboard / CVE

    Unknown

    CVE-1999-0658

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "DCOM is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0659

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A Windows NT Primary Domain Controller (PDC) or Backup Domain Controller (BDC) is present.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0660

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is not about any specific product, protocol, or design, so it is out of scope of CVE. It might be more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A hacker utility, back door, or Trojan Horse is installed on a system, e.g. NetBus, Back Orifice, Rootkit, etc.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0698

    Last Modified: 16 Apr 2026

    Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.

    Published: 1 Jan 1999
    7.5
    High

    CVE-1999-0651

    Last Modified: 16 Apr 2026

    The rsh/rlogin service is running.

    Published: 1 Jan 1999
    5
    Medium

    CVE-1999-0231

    Last Modified: 16 Apr 2026

    Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0248

    Last Modified: 16 Apr 2026

    A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.

    Published: 1 Jan 1999
    7.5
    High

    CVE-1999-0276

    Last Modified: 16 Apr 2026

    mSQL v2.0.1 and below allows remote execution through a buffer overflow.

    Published: 1 Jan 1999
    4.6
    Medium

    CVE-1999-0384

    Last Modified: 16 Apr 2026

    The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.

    Published: 1 Jan 1999
    5.1
    Medium

    CVE-1999-0395

    Last Modified: 16 Apr 2026

    A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.

    Published: 1 Jan 1999
    7.5
    High

    CVE-1999-0399

    Last Modified: 16 Apr 2026

    The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands.

    Published: 1 Jan 1999
    5
    Medium

    CVE-1999-0448

    Last Modified: 16 Apr 2026

    IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0547

    Last Modified: 16 Apr 2026

    An SSH server allows authentication through the .rhosts file.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0560

    Last Modified: 16 Apr 2026

    A system-critical Windows NT file or directory has inappropriate permissions.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0569

    Last Modified: 16 Apr 2026

    A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0570

    Last Modified: 16 Apr 2026

    Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.

    Published: 1 Jan 1999
    4.6
    Medium

    CVE-1999-0578

    Last Modified: 16 Apr 2026

    A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0587

    Last Modified: 16 Apr 2026

    A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.

    Published: 1 Jan 1999
    4.9
    Medium

    CVE-1999-0593

    Last Modified: 16 Apr 2026

    The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0596

    Last Modified: 16 Apr 2026

    A Windows NT log file has an inappropriate maximum size or retention period.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0602

    Last Modified: 16 Apr 2026

    A network intrusion detection system (IDS) does not properly reassemble fragmented packets.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0618

    Last Modified: 16 Apr 2026

    The rexec service is running.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0630

    Last Modified: 16 Apr 2026

    The NT Alerter and Messenger services are running.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0641

    Last Modified: 16 Apr 2026

    The UUCP service is running.

    Published: 1 Jan 1999
    5
    Medium

    CVE-1999-0650

    Last Modified: 16 Apr 2026

    The netstat service is running, which provides sensitive information to remote attackers.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0657

    Last Modified: 16 Apr 2026

    WinGate is being used.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0663

    Last Modified: 16 Apr 2026

    A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0665

    Last Modified: 16 Apr 2026

    An application-critical Windows NT registry key has an inappropriate value.

    Published: 1 Jan 1999
    5.1
    Medium

    CVE-1999-1440

    Last Modified: 16 Apr 2026

    Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client.

    Published: 1 Jan 1999
    7.5
    High

    CVE-1999-1568

    Last Modified: 16 Apr 2026

    Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.

    Published: 1 Jan 1999
    5
    Medium

    CVE-1999-0205

    Last Modified: 16 Apr 2026

    Denial of service in Sendmail 8.6.11 and 8.6.12.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0226

    Last Modified: 16 Apr 2026

    Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0361

    Last Modified: 16 Apr 2026

    NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.

    Published: 1 Jan 1999
    5
    Medium

    CVE-1999-0393

    Last Modified: 16 Apr 2026

    Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.

    Published: 1 Jan 1999
    6.4
    Medium

    CVE-1999-0520

    Last Modified: 16 Apr 2026

    A system-critical NETBIOS/SMB share has inappropriate access control.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0531

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "An SMTP service supports EXPN, VRFY, HELP, ESMTP, and/or EHLO.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0565

    Last Modified: 16 Apr 2026

    A Sendmail alias allows input to be piped to a program.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0583

    Last Modified: 16 Apr 2026

    There is a one-way or two-way trust relationship between Windows NT domains.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0577

    Last Modified: 16 Apr 2026

    A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0603

    Last Modified: 16 Apr 2026

    In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0594

    Last Modified: 16 Apr 2026

    A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0600

    Last Modified: 16 Apr 2026

    A network intrusion detection system (IDS) does not verify the checksum on a packet.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0621

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A component service related to NETBIOS is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0631

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The NFS service is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0643

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The IMAP service is running.

    Published: 1 Jan 1999
    Unknown

    CVE-1999-0644

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The NNTP news service is running.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0661

    Last Modified: 16 Apr 2026

    A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.

    Published: 1 Jan 1999
    10
    Critical

    CVE-1999-0664

    Last Modified: 16 Apr 2026

    An application-critical Windows NT registry key has inappropriate permissions.

    Published: 1 Jan 1999
    2.1
    Low

    CVE-1999-1430

    Last Modified: 16 Apr 2026

    PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.

    Published: 1 Jan 1999
    0
    Low

    CVE-1999-0613

    Last Modified: 16 Apr 2026

    The rpc.sprayd service is running.

    Published: 1 Jan 1999