Search
Total
86024 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-1999-0571 | 2005-10-20 | 10.0 HIGH | N/A | ||
| A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts. | |||||
| CVE-1999-0520 | 2005-10-20 | 6.4 MEDIUM | N/A | ||
| A system-critical NETBIOS/SMB share has inappropriate access control. | |||||
| CVE-1999-0654 | 2005-10-20 | 10.0 HIGH | N/A | ||
| The OS/2 or POSIX subsystem in NT is enabled. | |||||
| CVE-1999-0555 | 2005-10-20 | 10.0 HIGH | N/A | ||
| A Unix account with a name other than "root" has UID 0, i.e. root privileges. | |||||
| CVE-1999-0397 | 2005-10-20 | 10.0 HIGH | N/A | ||
| The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext. | |||||
| CVE-1999-0653 | 2005-10-20 | 10.0 HIGH | N/A | ||
| A component service related to NIS+ is running. | |||||
| CVE-1999-0394 | 2005-10-20 | 10.0 HIGH | N/A | ||
| DPEC Online Courseware allows an attacker to change another user's password without knowing the original password. | |||||
| CVE-1999-0361 | 2005-10-20 | 10.0 HIGH | N/A | ||
| NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging. | |||||
| CVE-1999-0636 | 2005-10-20 | 10.0 HIGH | N/A | ||
| The discard service is running. | |||||
| CVE-1999-0584 | 2005-10-20 | 10.0 HIGH | N/A | ||
| A Windows NT file system is not NTFS. | |||||
| CVE-1999-0944 | 2005-10-20 | 10.0 HIGH | N/A | ||
| IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections. | |||||
| CVE-1999-0583 | 2005-10-20 | 10.0 HIGH | N/A | ||
| There is a one-way or two-way trust relationship between Windows NT domains. | |||||
| CVE-1999-0569 | 2005-10-20 | 10.0 HIGH | N/A | ||
| A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. | |||||
| CVE-1999-0197 | 2005-10-20 | 10.0 HIGH | N/A | ||
| finger 0@host on some systems may print information on some user accounts. | |||||
| CVE-1999-0200 | 2005-10-20 | 10.0 HIGH | N/A | ||
| Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password. | |||||
| CVE-1999-0530 | 2005-10-20 | 10.0 HIGH | N/A | ||
| A system is operating in "promiscuous" mode which allows it to perform packet sniffing. | |||||
| CVE-1999-0529 | 2005-10-20 | 7.5 HIGH | N/A | ||
| A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc. | |||||
| CVE-1999-0528 | 2005-10-20 | 7.5 HIGH | N/A | ||
| A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of. | |||||
| CVE-1999-0527 | 2005-10-20 | 10.0 HIGH | N/A | ||
| The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten. | |||||
| CVE-1999-0495 | 2005-10-20 | 10.0 HIGH | N/A | ||
| A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares. | |||||
| CVE-2003-0565 | 2005-10-20 | 5.0 MEDIUM | N/A | ||
| Multiple vulnerabilities in multiple vendor implementations of the X.400 protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an X.400 message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite. | |||||
| CVE-1999-0937 | 2005-05-02 | 10.0 HIGH | N/A | ||
| BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable. | |||||
| CVE-1999-0936 | 2005-05-02 | 10.0 HIGH | N/A | ||
| BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters. | |||||
| CVE-1999-0935 | 2005-05-02 | 10.0 HIGH | N/A | ||
| classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form. | |||||
