Skip to main content

Severity archive

Critical severity CVEs

Critical

43,592 critical severity CVEs — 43,592 Critical, 125,443 High, 163,751 Medium, 17,997 Low, 2,140 Unrated across the current result set.

CVE-1999-0489

Published May 17, 1999

MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in M…

CVSS 10.0 · Critical
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-0754

Published May 11, 1999

The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1241

Published May 6, 1999

Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX obje…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1553

Published May 1, 1999

Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0492

Published Apr 23, 1999

The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.

CVSS 10.0 · Critical

CVE-1999-0801

Published Apr 9, 1999

BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0443

Published Apr 1, 1999

Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0426

Published Mar 1, 1999

The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1046

Published Mar 1, 1999

Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0408

Published Feb 25, 1999

Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1049

Published Feb 21, 1999

ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1405

Published Feb 17, 1999

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which coul…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0353

Published Feb 10, 1999

rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.

CVSS 9.3 · Critical
Buzz score
12.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-1999-0407

Published Feb 9, 1999

By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.

CVSS 10.0 · Critical
Buzz score
10.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2000-0370

Published Jan 29, 1999

The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0461

Published Jan 28, 1999

Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0347

Published Jan 26, 1999

Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use t…

CVSS 10.0 · Critical

CVE-1999-0356

Published Jan 25, 1999

ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.

CVSS 10.0 · Critical
Buzz score
18.0
Public PoC observed

CVE-1999-0119

Published Jan 19, 1999

Windows NT 4.0 beta allows users to read and delete shares.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1376

Published Jan 14, 1999

Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0197

Published Jan 1, 1999

finger 0@host on some systems may print information on some user accounts.

CVSS 10.0 · Critical

CVE-1999-0198

Published Jan 1, 1999

finger .@host on some systems may print information on some user accounts.

CVSS 10.0 · Critical

CVE-1999-0200

Published Jan 1, 1999

Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.

CVSS 10.0 · Critical

CVE-1999-0220

Published Jan 1, 1999

Attackers can do a denial of service of IRC by crashing the server.

CVSS 10.0 · Critical
Showing 43,501-43,525 of 43,592 CVEsPage 1741 of 1744