Skip to main content

Severity archive

Critical severity CVEs

Critical

43,458 critical severity CVEs — 43,458 Critical, 125,144 High, 163,487 Medium, 17,970 Low, 2,179 Unrated across the current result set.

CVE-1999-0394

Published Jan 1, 1999

DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.

CVSS 10.0 · Critical

CVE-1999-0397

Published Jan 1, 1999

The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.

CVSS 10.0 · Critical

CVE-1999-0452

Published Jan 1, 1999

A service or application has a backdoor password that was placed there by the developer.

CVSS 10.0 · Critical

CVE-1999-0454

Published Jan 1, 1999

A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.

CVSS 10.0 · Critical
Buzz score
10.4
Public PoC observed

CVE-1999-0465

Published Jan 1, 1999

Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.

CVSS 10.0 · Critical

CVE-1999-0495

Published Jan 1, 1999

A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.

CVSS 10.0 · Critical

CVE-1999-0512

Published Jan 1, 1999

A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.

CVSS 10.0 · Critical

CVE-1999-0515

Published Jan 1, 1999

An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.

CVSS 10.0 · Critical

CVE-1999-0527

Published Jan 1, 1999

The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable,…

CVSS 10.0 · Critical
Buzz score
4.4
Public PoC observed

CVE-1999-0530

Published Jan 1, 1999

A system is operating in "promiscuous" mode which allows it to perform packet sniffing.

CVSS 10.0 · Critical

CVE-1999-0539

Published Jan 1, 1999

A trust relationship exists between two Unix hosts.

CVSS 10.0 · Critical

CVE-1999-0547

Published Jan 1, 1999

An SSH server allows authentication through the .rhosts file.

CVSS 10.0 · Critical

CVE-1999-0548

Published Jan 1, 1999

A superfluous NFS server is running, but it is not importing or exporting any file systems.

CVSS 10.0 · Critical
Buzz score
4.0
OTX pulse activity

CVE-1999-0554

Published Jan 1, 1999

NFS exports system-critical data to the world, e.g. / or a password file.

CVSS 10.0 · Critical
Buzz score
8.4
Public PoC observedOTX pulse activity

CVE-1999-0555

Published Jan 1, 1999

A Unix account with a name other than "root" has UID 0, i.e. root privileges.

CVSS 10.0 · Critical

CVE-1999-0556

Published Jan 1, 1999

Two or more Unix accounts have the same UID.

CVSS 10.0 · Critical

CVE-1999-0559

Published Jan 1, 1999

A system-critical Unix file or directory has inappropriate permissions.

CVSS 10.0 · Critical
Buzz score
6.0
Public PoC observed

CVE-1999-0560

Published Jan 1, 1999

A system-critical Windows NT file or directory has inappropriate permissions.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0561

Published Jan 1, 1999

IIS has the #exec function enabled for Server Side Include (SSI) files.

CVSS 10.0 · Critical
Buzz score
10.4
Public PoC observed

CVE-1999-0564

Published Jan 1, 1999

An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.

CVSS 10.0 · Critical

CVE-1999-0565

Published Jan 1, 1999

A Sendmail alias allows input to be piped to a program.

CVSS 10.0 · Critical
Buzz score
6.0
Public PoC observed

CVE-1999-0568

Published Jan 1, 1999

rpc.admind in Solaris is not running in a secure mode.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0569

Published Jan 1, 1999

A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.

CVSS 10.0 · Critical

CVE-1999-0570

Published Jan 1, 1999

Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 43,401-43,425 of 43,458 CVEsPage 1737 of 1739