Latest CVE Feed
-
7.5
HIGHCVE-1999-1087
Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unau... Read more
Affected Products : internet_explorer- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1074
Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.... Read more
Affected Products : webmin- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1175
Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.... Read more
Affected Products : ios- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1465
Vulnerability in Cisco IOS 11.1 through 11.3 with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled input interface to an output interface with a log... Read more
Affected Products : ios- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-0154
IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.... Read more
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1316
Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.... Read more
Affected Products : windows_nt- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1333
automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.... Read more
Affected Products : linux- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1332
gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.... Read more
Affected Products : linux- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-1999-1386
Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.... Read more
Affected Products : perl- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1473
When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue."... Read more
Affected Products : internet_explorer- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1294
Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permiss... Read more
Affected Products : windows_nt- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-1585
The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.... Read more
Affected Products : sunos- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-1325
SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges.... Read more
Affected Products : sas_system- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1456
thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.... Read more
Affected Products : thttpd_http_server- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1587
/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.... Read more
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1279
An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.... Read more
Affected Products : sna_server- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1043
Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).... Read more
Affected Products : exchange_server- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1474
PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide show, when the document is opened in browsers such as Internet Explorer.... Read more
Affected Products : powerpoint- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1364
Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.... Read more
Affected Products : windows_nt- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1455
RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authori... Read more
Affected Products : windows_nt- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025