Latest CVE Feed
-
5.0
MEDIUMCVE-1999-1456
thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.... Read more
Affected Products : thttpd_http_server- EPSS Score: %1.08
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1126
Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_d... Read more
Affected Products : resource_manager- EPSS Score: %0.08
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1177
Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the pathname for an upload operation.... Read more
Affected Products : nph-publish- EPSS Score: %0.95
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1455
RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authori... Read more
Affected Products : windows_nt- EPSS Score: %6.95
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1339
Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command.... Read more
- EPSS Score: %1.11
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-1999-1590
Directory traversal vulnerability in Muhammad A. Muquit wwwcount (Count.cgi) 2.3 allows remote attackers to read arbitrary GIF files via ".." sequences in the image parameter, a different vulnerability than CVE-1999-0021.... Read more
Affected Products : wwwcount- EPSS Score: %0.16
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1451
The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.... Read more
- EPSS Score: %35.59
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-1999-1358
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by t... Read more
- EPSS Score: %0.23
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1444
genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.... Read more
Affected Products : alibaba- EPSS Score: %0.61
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1100
Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper ke... Read more
Affected Products : pix_private_link- EPSS Score: %0.53
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-1588
Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.... Read more
Affected Products : solaris- EPSS Score: %6.85
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1132
Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.... Read more
Affected Products : windows_nt- EPSS Score: %19.46
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1316
Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.... Read more
Affected Products : windows_nt- EPSS Score: %6.95
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1233
IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.... Read more
Affected Products : internet_information_server- EPSS Score: %10.31
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1206
SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a m... Read more
Affected Products : systemwizard- EPSS Score: %1.32
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-1999-1104
Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.... Read more
Affected Products : windows_95- EPSS Score: %0.57
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1124
HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the req... Read more
Affected Products : coldfusion- EPSS Score: %0.31
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-0815
Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.... Read more
Affected Products : windows_nt- EPSS Score: %17.10
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1094
Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."... Read more
Affected Products : internet_explorer- EPSS Score: %6.93
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1334
Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument.... Read more
Affected Products : elm- EPSS Score: %0.74
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025