Latest CVE Feed
-
5.0
MEDIUMCVE-1999-1132
Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.... Read more
Affected Products : windows_nt- EPSS Score: %19.46
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1334
Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument.... Read more
Affected Products : elm- EPSS Score: %0.74
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1094
Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."... Read more
Affected Products : internet_explorer- EPSS Score: %6.93
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-1999-1104
Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.... Read more
Affected Products : windows_95- EPSS Score: %0.57
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1124
HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the req... Read more
Affected Products : coldfusion- EPSS Score: %0.31
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-1999-1093
Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.... Read more
Affected Products : internet_explorer- EPSS Score: %6.27
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-1999-1084
The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.... Read more
Affected Products : windows_nt- EPSS Score: %0.76
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-0815
Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.... Read more
Affected Products : windows_nt- EPSS Score: %17.10
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-1999-1358
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by t... Read more
- EPSS Score: %0.23
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-1588
Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.... Read more
Affected Products : solaris- EPSS Score: %6.85
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1177
Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the pathname for an upload operation.... Read more
Affected Products : nph-publish- EPSS Score: %0.95
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1175
Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.... Read more
Affected Products : ios- EPSS Score: %0.87
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1074
Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.... Read more
Affected Products : webmin- EPSS Score: %0.85
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-0808
Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.... Read more
Affected Products : dhcp_client- EPSS Score: %1.58
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-1586
loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584.... Read more
Affected Products : sunos- EPSS Score: %0.08
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-1307
Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.... Read more
Affected Products : unixware- EPSS Score: %0.03
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1035
IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.... Read more
Affected Products : internet_information_server- EPSS Score: %18.09
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-1999-1167
Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.... Read more
Affected Products : third_voice_web- EPSS Score: %0.65
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1259
Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information.... Read more
Affected Products : office- EPSS Score: %1.93
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1456
thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.... Read more
Affected Products : thttpd_http_server- EPSS Score: %1.08
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025