Skip to main content

Severity archive

Critical severity CVEs

Critical

43,592 critical severity CVEs — 43,592 Critical, 125,443 High, 163,751 Medium, 17,997 Low, 2,140 Unrated across the current result set.

CVE-1999-0226

Published Jan 1, 1999

Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0243

Published Jan 1, 1999

Linux cfingerd could be exploited to gain root access.

CVSS 10.0 · Critical

CVE-1999-0248

Published Jan 1, 1999

A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0255

Published Jan 1, 1999

Buffer overflow in ircd allows arbitrary command execution.

CVSS 10.0 · Critical

CVE-1999-0268

Published Jan 1, 1999

MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0283

Published Jan 1, 1999

The Java Web Server would allow remote users to obtain the source code for CGI programs.

CVSS 10.0 · Critical

CVE-1999-0285

Published Jan 1, 1999

Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0286

Published Jan 1, 1999

In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.

CVSS 10.0 · Critical

CVE-1999-0361

Published Jan 1, 1999

NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.

CVSS 10.0 · Critical
Buzz score
3.5
Public PoC observed

CVE-1999-0394

Published Jan 1, 1999

DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.

CVSS 10.0 · Critical

CVE-1999-0397

Published Jan 1, 1999

The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.

CVSS 10.0 · Critical

CVE-1999-0452

Published Jan 1, 1999

A service or application has a backdoor password that was placed there by the developer.

CVSS 10.0 · Critical

CVE-1999-0454

Published Jan 1, 1999

A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.

CVSS 10.0 · Critical
Buzz score
10.4
Public PoC observed

CVE-1999-0465

Published Jan 1, 1999

Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.

CVSS 10.0 · Critical

CVE-1999-0495

Published Jan 1, 1999

A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.

CVSS 10.0 · Critical

CVE-1999-0512

Published Jan 1, 1999

A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.

CVSS 10.0 · Critical

CVE-1999-0515

Published Jan 1, 1999

An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.

CVSS 10.0 · Critical

CVE-1999-0527

Published Jan 1, 1999

The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable,…

CVSS 10.0 · Critical
Buzz score
4.4
Public PoC observed

CVE-1999-0530

Published Jan 1, 1999

A system is operating in "promiscuous" mode which allows it to perform packet sniffing.

CVSS 10.0 · Critical

CVE-1999-0539

Published Jan 1, 1999

A trust relationship exists between two Unix hosts.

CVSS 10.0 · Critical

CVE-1999-0547

Published Jan 1, 1999

An SSH server allows authentication through the .rhosts file.

CVSS 10.0 · Critical

CVE-1999-0548

Published Jan 1, 1999

A superfluous NFS server is running, but it is not importing or exporting any file systems.

CVSS 10.0 · Critical
Buzz score
4.0
OTX pulse activity

CVE-1999-0554

Published Jan 1, 1999

NFS exports system-critical data to the world, e.g. / or a password file.

CVSS 10.0 · Critical
Buzz score
8.4
Public PoC observedOTX pulse activity

CVE-1999-0555

Published Jan 1, 1999

A Unix account with a name other than "root" has UID 0, i.e. root privileges.

CVSS 10.0 · Critical
Showing 43,526-43,550 of 43,592 CVEsPage 1742 of 1744