Skip to main content

Severity archive

Critical severity CVEs

Critical

43,458 critical severity CVEs — 43,458 Critical, 125,140 High, 163,487 Medium, 17,970 Low, 2,150 Unrated across the current result set.

CVE-1999-0408

Published Feb 25, 1999

Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1049

Published Feb 21, 1999

ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1405

Published Feb 17, 1999

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which coul…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0353

Published Feb 10, 1999

rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.

CVSS 9.3 · Critical
Buzz score
12.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-1999-0407

Published Feb 9, 1999

By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.

CVSS 10.0 · Critical
Buzz score
10.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2000-0370

Published Jan 29, 1999

The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0461

Published Jan 28, 1999

Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0347

Published Jan 26, 1999

Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use t…

CVSS 10.0 · Critical

CVE-1999-0356

Published Jan 25, 1999

ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.

CVSS 10.0 · Critical
Buzz score
18.0
Public PoC observed

CVE-1999-0119

Published Jan 19, 1999

Windows NT 4.0 beta allows users to read and delete shares.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1376

Published Jan 14, 1999

Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0197

Published Jan 1, 1999

finger 0@host on some systems may print information on some user accounts.

CVSS 10.0 · Critical

CVE-1999-0198

Published Jan 1, 1999

finger .@host on some systems may print information on some user accounts.

CVSS 10.0 · Critical

CVE-1999-0200

Published Jan 1, 1999

Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.

CVSS 10.0 · Critical

CVE-1999-0220

Published Jan 1, 1999

Attackers can do a denial of service of IRC by crashing the server.

CVSS 10.0 · Critical

CVE-1999-0226

Published Jan 1, 1999

Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0243

Published Jan 1, 1999

Linux cfingerd could be exploited to gain root access.

CVSS 10.0 · Critical

CVE-1999-0248

Published Jan 1, 1999

A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0255

Published Jan 1, 1999

Buffer overflow in ircd allows arbitrary command execution.

CVSS 10.0 · Critical

CVE-1999-0268

Published Jan 1, 1999

MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0283

Published Jan 1, 1999

The Java Web Server would allow remote users to obtain the source code for CGI programs.

CVSS 10.0 · Critical

CVE-1999-0285

Published Jan 1, 1999

Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0286

Published Jan 1, 1999

In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.

CVSS 10.0 · Critical

CVE-1999-0361

Published Jan 1, 1999

NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.

CVSS 10.0 · Critical
Buzz score
3.5
Public PoC observed
Showing 43,376-43,400 of 43,458 CVEsPage 1736 of 1739