CVE-1999-1110
Published Nov 14, 1999Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine…
Loading current evidence
Historical archive search
Search decades of CVEs by regex, severity, date, CWE, vendor/product tags, KEV, PoC, and other evidence.
Results
163,219 results · Sorted by Highest Buzz score first
Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine…
ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same syst…
Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachme…
Denial of service in BIND named via consuming more than "fdmax" file descriptors.
Denial of service in BIND named via maxdname.
FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument.
Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI.
bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter.
Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port.
FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.
Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL.
Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username.
Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag.
HP Secure Web Console uses weak encryption.
Ultimate Bulletin Board stores data files in the cgi-bin directory, allowing remote attackers to view the data if an error occurs when the HTTP server attempts to execute the file.
Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings…
Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO commands.
Falcon web server allows remote attackers to determine the absolute path of the web root via long file names.
URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the "Log Out" option and selecting a "Cancel" option in the di…
LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) S…
The Zeus web server administrative interface uses weak encryption for its passwords.
Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory.
Denial of service in Axent Raptor firewall via malformed zero-length IP options.
Every filter state lives in the URL so you can bookmark, share, and crawl exact historical slices instead of a client-only search session.
Buzz order uses the latest all-time evidence snapshot, refreshed every two hours. Evidence-bearing CVEs rank first; records without a snapshot continue newest-first.