5.9
    Medium

    CVE-1999-0517

    Last Modified: 28 May 2026

    An SNMP community name is the default (e.g. public), null, or missing.

    Published:1 Jan 1997
    5
    Medium

    CVE-1999-0513

    Last Modified: 21 Sept 2016

    ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.

    Source:T. Freak
    Published:5 Jan 1998
    7.5
    High

    CVE-1999-0504

    Last Modified: 8 Mar 2011

    A Windows NT local user or administrator account has a default, null, blank, or missing password.

    Source:Metasploit
    Published:1 Jan 1997
    7.5
    High

    CVE-1999-0502

    Last Modified: 23 Mar 2017

    A Unix account has a default, null, blank, or missing password.

    Source:Metasploit
    Published:1 Mar 1998
    7.5
    High

    CVE-1999-0493

    Last Modified: 21 Jun 2012

    rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.

    Source:anonymous
    Published:7 Jun 1999
    10
    Critical

    CVE-1999-0492

    Last Modified: 8 Aug 2012

    The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.

    Source:Eilon Gishri
    Published:23 Apr 1999
    4.6
    Medium

    CVE-1999-0491

    Last Modified: 12 Jun 2012

    The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.

    Source:Shadow
    Published:20 Apr 1999
    2.6
    Low

    CVE-1999-0487

    Last Modified: 15 Sept 2017

    The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.

    Source:Georgi Guninsky
    Published:1 May 1999
    7.5
    High

    CVE-1999-0477

    Last Modified: 12 Jun 2012

    The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.

    Source:rain.forest.puppy
    Published:25 Dec 1999
    5
    Medium

    CVE-1999-0470

    Last Modified: 22 Jun 2012

    A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.

    Source:dreamer
    Published:9 Apr 1999
    5
    Medium

    CVE-1999-0467

    Last Modified: 12 Aug 2012

    The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the "template" parameter.

    Source:Mnemonix
    Published:1 Apr 1999
    2.1
    Low

    CVE-1999-0460

    Last Modified: 22 Nov 2017

    Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.

    Source:Brian Jones
    Published:19 Feb 1999
    7.5
    High

    CVE-1999-0455

    Last Modified: 12 Jun 2012

    The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.

    Source:rain.forest.puppy
    Published:25 Dec 1999
    2.1
    Low

    CVE-1999-0451

    Last Modified: 6 Sept 2016

    Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.

    Source:David Schwartz
    Published:19 Jan 1999
    7.5
    High

    CVE-1999-0450

    Last Modified: 14 Jun 2012

    In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).

    Source:Mnemonix
    Published:26 Jan 1999
    5
    Medium

    CVE-1999-0448

    Last Modified: 31 Mar 2017

    IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.

    Source:Mnemonix
    Published:1 Jan 1999
    2.1
    Low

    CVE-1999-0442

    Last Modified: 16 Nov 2017

    Solaris ff.core allows local users to modify files.

    Source:John McDonald
    Published:7 Jan 1999
    5
    Medium

    CVE-1999-0441

    Last Modified: 27 Jun 2012

    Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.

    Source:Prizm
    Published:22 Feb 1999
    4.6
    Medium

    CVE-1999-0433

    Last Modified: 17 Jun 2012

    XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.

    Source:Stealthf0rk
    Published:21 Mar 1999
    5
    Medium

    CVE-1999-0431

    Last Modified: 16 Aug 2012

    Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service.

    Source:John McDonald
    Published:1 Mar 1999
    9.8
    Critical

    CVE-1999-0426

    Last Modified: 30 Jun 2012

    The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.

    Source:Nergal
    Published:1 Mar 1999
    2.1
    Low

    CVE-1999-0417

    Last Modified: 15 Nov 2017

    64 bit Solaris 7 procfs allows local users to perform a denial of service.

    Source:Toomas Soome
    Published:9 Mar 1999
    5
    Medium

    CVE-1999-0416

    Last Modified: 18 Jul 2012

    Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port.

    Source:Tiz.Telesup
    Published:11 Mar 1999
    5
    Medium

    CVE-1999-0414

    Last Modified: 30 Jun 2012

    In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.

    Source:Nergal
    Published:1 Mar 1999
    7.5
    High

    CVE-1999-0412

    Last Modified: 23 Jun 2012

    In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.

    Source:Fabien Royer
    Published:19 Feb 1999
    7.2
    High

    CVE-1999-0410

    Last Modified: 16 Nov 2017

    The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.

    Source:Josh A. Strickland
    Published:5 Mar 1999
    4.6
    Medium

    CVE-1999-0409

    Last Modified: 22 Nov 2017

    Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.

    Source:xnec
    Published:4 Mar 1999
    7.2
    High

    CVE-1999-0405

    Last Modified: 15 Nov 2017

    A buffer overflow in lsof allows local users to obtain root privilege.

    Source:c0nd0r
    Published:18 Feb 1999
    7.5
    High

    CVE-1999-0404

    Last Modified: 17 Aug 2012

    Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.

    Source:_mcp_
    Published:14 Feb 1999
    4.6
    Medium

    CVE-1999-0400

    Last Modified: 18 Jun 2012

    Denial of service in Linux 2.2.0 running the ldd command on a core file.

    Source:Dan Burcaw
    Published:26 Jan 1999
    5
    Medium

    CVE-1999-0393

    Last Modified: 15 Nov 2017

    Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.

    Source:marchew
    Published:1 Jan 1999
    4.6
    Medium

    CVE-1999-0388

    Last Modified: 15 Nov 2017

    DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.

    Source:Dr. Mudge
    Published:1 Jan 1999
    5
    Medium

    CVE-1999-0386

    Last Modified: 11 Jul 2012

    Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.

    Source:kiborg
    Published:1 Mar 1999
    7.2
    High

    CVE-1999-0382

    Last Modified: 22 Jun 2012

    The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.

    Source:Cybermedia Software Private Limited
    Published:12 Mar 1999
    7.2
    High

    CVE-1999-0381

    Last Modified: 15 Nov 2017

    super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.

    Source:c0nd0r
    Published:26 Feb 1999
    4.6
    Medium

    CVE-1999-0376

    Last Modified: 16 Jun 2012

    Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.

    Source:L0pht
    Published:20 Feb 1999
    2.1
    Low

    CVE-1999-0372

    Last Modified: 16 Jun 2012

    The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.

    Source:Russ Cooper
    Published:12 Feb 1999
    7.2
    High

    CVE-1999-0369

    Last Modified: 16 Nov 2017

    The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.

    Source:UNYUN
    Published:1 Feb 1997
    10
    Critical

    CVE-1999-0368

    Last Modified: 16 Nov 2017

    Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.

    Source:smiler & cossack
    Published:9 Feb 1999
    7.2
    High

    CVE-1999-0363

    Last Modified: 17 Jun 2012

    SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.

    Source:xnec
    Published:2 Feb 1999
    7.2
    High

    CVE-1999-0360

    Last Modified: 7 Aug 2012

    MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.

    Source:Mnemonix
    Published:30 Jan 1999
    6.2
    Medium

    CVE-1999-0350

    Last Modified: 27 Jun 2012

    Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.

    Source:Mudge
    Published:8 Feb 1999
    10
    Critical

    CVE-1999-0347

    Last Modified: 14 Jun 2012

    Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.

    Source:Georgi Guninski
    Published:26 Jan 1999
    Low

    CVE-1999-0335

    Last Modified: 15 Nov 2017

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0032. Reason: This candidate is a duplicate of CVE-1999-0032. Notes: All CVE users should reference CVE-1999-0032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Vadim Kolontsov
    Published:1 Aug 1996
    7.2
    High

    CVE-1999-0328

    Last Modified: 20 Jun 2012

    SGI permissions program allows local users to gain root privileges.

    Source:David Hedley
    Published:1 Nov 1997
    7.2
    High

    CVE-1999-0321

    Last Modified: 22 Jun 2012

    Buffer overflow in Solaris kcms_configure command allows local users to gain root access.

    Source:Cheez Whiz
    Published:1 Dec 1998
    7.2
    High

    CVE-1999-0315

    Last Modified: 16 Apr 2026

    Buffer overflow in Solaris fdformat command gives root access to local users.

    Source:Cristian Schipor
    Published:1 Apr 1997
    7.2
    High

    CVE-1999-0314

    Last Modified: 14 Jun 2012

    ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.

    Source:Loneguard
    Published:1 Jul 1998
    7.2
    High

    CVE-1999-0306

    Last Modified: 15 Nov 2017

    buffer overflow in HP xlock program.

    Source:BeastMaster
    Published:4 Nov 1997
    7.2
    High

    CVE-1999-0301

    Last Modified: 14 Jun 2012

    Buffer overflow in SunOS/Solaris ps command.

    Source:Joe Zbiciak
    Published:1 Aug 1997