Skip to main content

Year archive

CVEs published in 1999

Archive summary

894 CVEs published in 1999 — 164 Critical, 263 High, 356 Medium, 98 Low, 13 Unrated.

CVE-1999-0417

Published Mar 9, 1999

64 bit Solaris 7 procfs allows local users to perform a denial of service.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-1999-0418

Published Mar 8, 1999

Denial of service in SMTP applications such as Sendmail, when a remote attacker (e.g. spammer) uses many "RCPT TO" commands in the same connection.

CVSS 6.4 · Medium

CVE-1999-1371

Published Mar 8, 1999

Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-1999-1567

Published Mar 8, 1999

Seapine Software TestTrack server allows a remote attacker to cause a denial of service (high CPU) via (1) TestTrackWeb.exe and (2) ttcgi.exe by connecting to port 99 and disconne…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0411

Published Mar 7, 1999

Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user t…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0410

Published Mar 5, 1999

The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0409

Published Mar 4, 1999

Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-1256

Published Mar 4, 1999

Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which a…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0019

Published Mar 4, 1999

IMail POP3 daemon uses weak encryption, which allows local users to read files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-1999-1551

Published Mar 2, 1999

Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0221

Published Mar 1, 1999

Denial of service of Ascend routers through port 150 (remote administration).

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0222

Published Mar 1, 1999

Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0223

Published Mar 1, 1999

Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-1999-0261

Published Mar 1, 1999

Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.

CVSS 5.0 · Medium

CVE-1999-0386

Published Mar 1, 1999

Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-0413

Published Mar 1, 1999

A buffer overflow in the SGI X server allows local users to gain root access through the X server font path.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0414

Published Mar 1, 1999

In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0419

Published Mar 1, 1999

When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial…

CVSS 5.0 · Medium

CVE-1999-0426

Published Mar 1, 1999

The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0429

Published Mar 1, 1999

The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0431

Published Mar 1, 1999

Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service.

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-0432

Published Mar 1, 1999

ftp on HP-UX 11.00 allows local users to gain privileges.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0435

Published Mar 1, 1999

MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 651-675 of 894 CVEsPage 27 of 36