Skip to main content

Severity archive

Critical severity CVEs

Critical

44,477 critical severity CVEs — 44,477 Critical, 128,967 High, 163,939 Medium, 18,264 Low, 2,009 Unrated across the current result set.

CVE-1999-1086

Published Jul 15, 1999

Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0353

Published Jun 28, 1999

Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0730

Published Jun 12, 1999

The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0775

Published Jun 10, 1999

Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1237

Published Jun 6, 1999

Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary comm…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1063

Published Jun 1, 1999

CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0765

Published May 19, 1999

SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0489

Published May 17, 1999

MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in M…

CVSS 10.0 · Critical
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-0754

Published May 11, 1999

The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1241

Published May 6, 1999

Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX obje…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1553

Published May 1, 1999

Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0492

Published Apr 23, 1999

The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.

CVSS 10.0 · Critical

CVE-1999-0801

Published Apr 9, 1999

BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0443

Published Apr 1, 1999

Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0426

Published Mar 1, 1999

The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1046

Published Mar 1, 1999

Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0408

Published Feb 25, 1999

Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1049

Published Feb 21, 1999

ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1405

Published Feb 17, 1999

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which coul…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0353

Published Feb 10, 1999

rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.

CVSS 9.3 · Critical
Buzz score
12.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-1999-0407

Published Feb 9, 1999

By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.

CVSS 10.0 · Critical
Buzz score
10.4
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 44,376-44,400 of 44,477 CVEsPage 1776 of 1780