Skip to main content

Severity archive

High severity CVEs

High

124,926 high severity CVEs — 43,427 Critical, 124,926 High, 163,439 Medium, 17,961 Low, 2,024 Unrated across the current result set.

CVE-1999-0774

Published Aug 31, 1999

Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-1999-1513

Published Aug 30, 1999

Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-on…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-1561

Published Aug 20, 1999

Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0325

Published Aug 20, 1999

The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.

CVSS 7.2 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-0725

Published Aug 19, 1999

When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".

CVSS 7.1 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-0734

Published Aug 19, 1999

A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0753

Published Aug 17, 1999

The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0679

Published Aug 13, 1999

Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0813

Published Aug 10, 1999

Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-1999-1227

Published Jul 30, 1999

Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-1999-1536

Published Jul 30, 1999

.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-1999-1078

Published Jul 29, 1999

WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-1017

Published Jul 28, 1999

Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to ex…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0323

Published Jul 28, 1999

The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.

CVSS 7.6 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-1018

Published Jul 27, 1999

IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0710

Published Jul 25, 1999

The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-1165

Published Jul 21, 1999

GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fin…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 124,801-124,825 of 124,926 CVEsPage 4993 of 4998