Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0571 2005-10-20 10.0 HIGH N/A
A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.
CVE-1999-0520 2005-10-20 6.4 MEDIUM N/A
A system-critical NETBIOS/SMB share has inappropriate access control.
CVE-1999-0654 2005-10-20 10.0 HIGH N/A
The OS/2 or POSIX subsystem in NT is enabled.
CVE-1999-0555 2005-10-20 10.0 HIGH N/A
A Unix account with a name other than "root" has UID 0, i.e. root privileges.
CVE-1999-0397 2005-10-20 10.0 HIGH N/A
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
CVE-1999-0653 2005-10-20 10.0 HIGH N/A
A component service related to NIS+ is running.
CVE-1999-0394 2005-10-20 10.0 HIGH N/A
DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.
CVE-1999-0361 2005-10-20 10.0 HIGH N/A
NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.
CVE-1999-0636 2005-10-20 10.0 HIGH N/A
The discard service is running.
CVE-1999-0584 2005-10-20 10.0 HIGH N/A
A Windows NT file system is not NTFS.
CVE-1999-0944 2005-10-20 10.0 HIGH N/A
IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.
CVE-1999-0583 2005-10-20 10.0 HIGH N/A
There is a one-way or two-way trust relationship between Windows NT domains.
CVE-1999-0569 2005-10-20 10.0 HIGH N/A
A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.
CVE-1999-0197 2005-10-20 10.0 HIGH N/A
finger 0@host on some systems may print information on some user accounts.
CVE-1999-0200 2005-10-20 10.0 HIGH N/A
Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.
CVE-1999-0530 2005-10-20 10.0 HIGH N/A
A system is operating in "promiscuous" mode which allows it to perform packet sniffing.
CVE-1999-0529 2005-10-20 7.5 HIGH N/A
A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.
CVE-1999-0528 2005-10-20 7.5 HIGH N/A
A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.
CVE-1999-0527 2005-10-20 10.0 HIGH N/A
The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten.
CVE-1999-0495 2005-10-20 10.0 HIGH N/A
A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.
CVE-2003-0565 2005-10-20 5.0 MEDIUM N/A
Multiple vulnerabilities in multiple vendor implementations of the X.400 protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an X.400 message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.
CVE-1999-0937 2005-05-02 10.0 HIGH N/A
BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.
CVE-1999-0936 2005-05-02 10.0 HIGH N/A
BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.
CVE-1999-0935 2005-05-02 10.0 HIGH N/A
classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.