1999 CVE Vulnerabilities

897 CVEs published in 1999.

CVE IDSeverityCVSSDescription
CVE-1999-0268——MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.
CVE-1999-0276——mSQL v2.0.1 and below allows remote execution through a buffer overflow.
CVE-1999-0283——The Java Web Server would allow remote users to obtain the source code for CGI programs.
CVE-1999-0285——Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
CVE-1999-0286——In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.
CVE-1999-0355——Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.
CVE-1999-0361——NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logg...
CVE-1999-0384——The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's c...
CVE-1999-0388——DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute command...
CVE-1999-0393——Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of he...
CVE-1999-0395——A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.
CVE-1999-0397——The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
CVE-1999-0398——In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.
CVE-1999-0399——The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attack...
CVE-1999-0401——A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.
CVE-1999-0448——IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL...
CVE-1999-0452——A service or application has a backdoor password that was placed there by the developer.
CVE-1999-0453——An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol ...
CVE-1999-0454——A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packet...
CVE-1999-0465——Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
CVE-1999-0495——A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.
CVE-1999-0497——Anonymous FTP is enabled.

Check if your code is affected by 1999 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now