Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-1999-1246

    Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.... Read more

    Affected Products : site_server
    • EPSS Score: %0.94
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-1999-1290

    Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string.... Read more

    Affected Products : nftp
    • EPSS Score: %0.62
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-1999-1358

    When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by t... Read more

    Affected Products : windows_2000 windows_nt
    • EPSS Score: %0.23
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-1999-1307

    Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.... Read more

    Affected Products : unixware
    • EPSS Score: %0.03
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-1999-1586

    loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584.... Read more

    Affected Products : sunos
    • EPSS Score: %0.08
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-1999-1100

    Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper ke... Read more

    Affected Products : pix_private_link
    • EPSS Score: %0.53
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-1999-1584

    Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerab... Read more

    Affected Products : sunos openwindows
    • EPSS Score: %0.48
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-1999-1339

    Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command.... Read more

    Affected Products : linux_kernel freebsd
    • EPSS Score: %1.11
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 3.5

    LOW
    CVE-1999-1590

    Directory traversal vulnerability in Muhammad A. Muquit wwwcount (Count.cgi) 2.3 allows remote attackers to read arbitrary GIF files via ".." sequences in the image parameter, a different vulnerability than CVE-1999-0021.... Read more

    Affected Products : wwwcount
    • EPSS Score: %0.16
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-1999-1315

    Vulnerabilities in DECnet/OSI for OpenVMS before 5.8 on DEC Alpha AXP and VAX/VMS systems allow local users to gain privileges or cause a denial of service.... Read more

    Affected Products : dec_openvms
    • EPSS Score: %0.06
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-1999-1455

    RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authori... Read more

    Affected Products : windows_nt
    • EPSS Score: %6.95
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-1360

    Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.... Read more

    Affected Products : windows_nt
    • EPSS Score: %0.37
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-1364

    Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.... Read more

    Affected Products : windows_nt
    • EPSS Score: %0.37
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-1999-1472

    Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue.... Read more

    Affected Products : internet_explorer
    • EPSS Score: %17.72
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-1999-1043

    Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).... Read more

    Affected Products : exchange_server
    • EPSS Score: %6.49
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-1999-1474

    PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide show, when the document is opened in browsers such as Internet Explorer.... Read more

    Affected Products : powerpoint
    • EPSS Score: %7.39
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-1999-1279

    An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.... Read more

    Affected Products : sna_server
    • EPSS Score: %14.00
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-1999-1444

    genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.... Read more

    Affected Products : alibaba
    • EPSS Score: %0.61
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-1999-1035

    IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.... Read more

    Affected Products : internet_information_server
    • EPSS Score: %18.09
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-1999-1167

    Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.... Read more

    Affected Products : third_voice_web
    • EPSS Score: %0.65
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
Showing 20 of 292485 Results