CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-1999-0521

    Last Modified: 16 Apr 2026

    An NIS domain name is easily guessable.

    Published: 1 Jan 1997
    7.5
    High

    CVE-1999-0519

    Last Modified: 16 Apr 2026

    A NETBIOS/SMB share password is the default, null, or missing.

    Published: 1 Jan 1997
    7.5
    High

    CVE-1999-0562

    Last Modified: 16 Apr 2026

    The registry in Windows NT can be accessed remotely by users who are not administrators.

    Published: 1 Jan 1997
    2.1
    Low

    CVE-1999-0171

    Last Modified: 16 Apr 2026

    Denial of service in syslog by sending it a large number of superfluous messages.

    Published: 1 Jan 1997
    5
    Medium

    CVE-1999-0274

    Last Modified: 16 Apr 2026

    Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.

    Published: 1 Jan 1997
    7.2
    High

    CVE-1999-0503

    Last Modified: 16 Apr 2026

    A Windows NT local user or administrator account has a guessable password.

    Published: 1 Jan 1997
    5
    Medium

    CVE-1999-0582

    Last Modified: 16 Apr 2026

    A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.

    Published: 1 Jan 1997
    5
    Medium

    CVE-1999-0251

    Last Modified: 16 Apr 2026

    Denial of service in talk program allows remote attackers to disrupt a user's display.

    Published: 1 Jan 1997
    7.5
    High

    CVE-1999-0252

    Last Modified: 16 Apr 2026

    Buffer overflow in listserv allows arbitrary command execution.

    Published: 1 Jan 1997
    7.5
    High

    CVE-1999-0170

    Last Modified: 16 Apr 2026

    Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.

    Published: 1 Jan 1997
    7.5
    High

    CVE-1999-0178

    Last Modified: 16 Apr 2026

    Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.

    Published: 1 Jan 1997
    7.5
    High

    CVE-1999-0253

    Last Modified: 16 Apr 2026

    IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.

    Published: 1 Jan 1997
    7.2
    High

    CVE-1999-0496

    Last Modified: 16 Apr 2026

    A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.

    Published: 1 Jan 1997
    9.1
    Critical

    CVE-1999-0511

    Last Modified: 28 May 2026

    IP forwarding is enabled on a machine which is not a router or firewall.

    Published: 1 Jan 1997
    10
    Critical

    CVE-1999-0204

    Last Modified: 16 Apr 2026

    Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.

    Published: 1 Jan 1997
    5
    Medium

    CVE-1999-0179

    Last Modified: 16 Apr 2026

    Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.

    Published: 1 Jan 1997
    2.1
    Low

    CVE-1999-1251

    Last Modified: 16 Apr 2026

    Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.

    Published: 24 Dec 1996
    7.5
    High

    CVE-1999-0260

    Last Modified: 16 Apr 2026

    The jj CGI program allows command execution via shell metacharacters.

    Published: 24 Dec 1996
    7.2
    High

    CVE-1999-1026

    Last Modified: 16 Apr 2026

    aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.

    Published: 20 Dec 1996
    7.2
    High

    CVE-1999-1385

    Last Modified: 16 Apr 2026

    Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.

    Published: 19 Dec 1996
    7.2
    High

    CVE-1999-0127

    Last Modified: 16 Apr 2026

    swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.

    Published: 19 Dec 1996
    5
    Medium

    CVE-1999-0128

    Last Modified: 16 Apr 2026

    Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.

    Published: 18 Dec 1996
    7.2
    High

    CVE-1999-1089

    Last Modified: 16 Apr 2026

    Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.

    Published: 13 Dec 1996
    7.2
    High

    CVE-1999-0297

    Last Modified: 16 Apr 2026

    Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.

    Published: 12 Dec 1996
    7.5
    High

    CVE-1999-0045

    Last Modified: 16 Apr 2026

    List of arbitrary files on Web host via nph-test-cgi script.

    Published: 10 Dec 1996
    5
    Medium

    CVE-1999-0096

    Last Modified: 16 Apr 2026

    Sendmail decode alias can be used to overwrite sensitive files.

    Published: 10 Dec 1996
    10
    Critical

    CVE-1999-0101

    Last Modified: 16 Apr 2026

    Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.

    Published: 10 Dec 1996
    4.6
    Medium

    CVE-1999-1401

    Last Modified: 16 Apr 2026

    Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).

    Published: 5 Dec 1996
    9.8
    Critical

    CVE-1999-0043

    Last Modified: 16 Apr 2026

    Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

    Published: 4 Dec 1996
    7.2
    High

    CVE-1999-0044

    Last Modified: 16 Apr 2026

    fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.

    Published: 3 Dec 1996
    4.6
    Medium

    CVE-1999-0129

    Last Modified: 16 Apr 2026

    Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.

    Published: 3 Dec 1996
    7.2
    High

    CVE-1999-0050

    Last Modified: 16 Apr 2026

    Buffer overflow in HP-UX newgrp program.

    Published: 1 Dec 1996
    7.5
    High

    CVE-1999-1240

    Last Modified: 16 Apr 2026

    Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.

    Published: 26 Nov 1996
    5
    Medium

    CVE-1999-1099

    Last Modified: 16 Apr 2026

    Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.

    Published: 22 Nov 1996
    2.1
    Low

    CVE-1999-1221

    Last Modified: 16 Apr 2026

    dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.

    Published: 17 Nov 1996
    7.2
    High

    CVE-1999-0130

    Last Modified: 16 Apr 2026

    Local users can start Sendmail in daemon mode and gain root privileges.

    Published: 16 Nov 1996
    7.2
    High

    CVE-1999-1161

    Last Modified: 16 Apr 2026

    Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.

    Published: 3 Nov 1996
    7.2
    High

    CVE-1999-0311

    Last Modified: 16 Apr 2026

    fpkg2swpk in HP-UX allows local users to gain root access.

    Published: 1 Nov 1996
    7.2
    High

    CVE-1999-0336

    Last Modified: 16 Apr 2026

    Buffer overflow in mstm in HP-UX allows local users to gain root access.

    Published: 1 Nov 1996
    7.2
    High

    CVE-1999-1384

    Last Modified: 16 Apr 2026

    Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.

    Published: 30 Oct 1996
    7.2
    High

    CVE-1999-0277

    Last Modified: 16 Apr 2026

    The WorkMan program can be used to overwrite any file to get root access.

    Published: 28 Oct 1996
    7.2
    High

    CVE-1999-0032

    Last Modified: 16 Apr 2026

    Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.

    Published: 25 Oct 1996
    5
    Medium

    CVE-1999-0075

    Last Modified: 16 Apr 2026

    PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.

    Published: 16 Oct 1996
    4.6
    Medium

    CVE-1999-0234

    Last Modified: 16 Apr 2026

    Bash treats any character with a value of 255 as a command separator.

    Published: 8 Oct 1996
    4.6
    Medium

    CVE-1999-0308

    Last Modified: 16 Apr 2026

    HP-UX gwind program allows users to modify arbitrary files.

    Published: 1 Oct 1996
    7.2
    High

    CVE-1999-0319

    Last Modified: 16 Apr 2026

    Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting.

    Published: 1 Oct 1996
    10
    Critical

    CVE-1999-0206

    Last Modified: 16 Apr 2026

    MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.

    Published: 1 Oct 1996
    10
    Critical

    CVE-1999-0246

    Last Modified: 16 Apr 2026

    HP Remote Watch allows a remote user to gain root access.

    Published: 1 Oct 1996
    6.2
    Medium

    CVE-1999-0961

    Last Modified: 16 Apr 2026

    HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.

    Published: 21 Sept 1996
    5
    Medium

    CVE-1999-0116

    Last Modified: 16 Apr 2026

    Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.

    Published: 19 Sept 1996