Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0944 2005-10-20 10.0 HIGH N/A
IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.
CVE-1999-0591 2005-10-20 10.0 HIGH N/A
An event log in Windows NT has inappropriate access permissions.
CVE-1999-0559 2005-10-20 10.0 HIGH N/A
A system-critical Unix file or directory has inappropriate permissions.
CVE-1999-0569 2005-10-20 10.0 HIGH N/A
A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.
CVE-1999-0571 2005-10-20 10.0 HIGH N/A
A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.
CVE-1999-0589 2005-10-20 10.0 HIGH N/A
A system-critical Windows NT registry key has inappropriate permissions.
CVE-1999-0548 2005-10-20 10.0 HIGH N/A
A superfluous NFS server is running, but it is not importing or exporting any file systems.
CVE-1999-0271 2005-10-20 5.0 MEDIUM N/A
Progressive Networks Real Video server (pnserver) can be crashed remotely.
CVE-2000-0889 2005-10-20 5.1 MEDIUM N/A
Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun.
CVE-1999-0584 2005-10-20 10.0 HIGH N/A
A Windows NT file system is not NTFS.
CVE-1999-0583 2005-10-20 10.0 HIGH N/A
There is a one-way or two-way trust relationship between Windows NT domains.
CVE-1999-0286 2005-10-20 10.0 HIGH N/A
In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.
CVE-1999-0561 2005-10-20 10.0 HIGH N/A
IIS has the #exec function enabled for Server Side Include (SSI) files.
CVE-1999-0564 2005-10-20 10.0 HIGH N/A
An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.
CVE-1999-0587 2005-10-20 10.0 HIGH N/A
A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.
CVE-1999-0361 2005-10-20 10.0 HIGH N/A
NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.
CVE-1999-0555 2005-10-20 10.0 HIGH N/A
A Unix account with a name other than "root" has UID 0, i.e. root privileges.
CVE-1999-0397 2005-10-20 10.0 HIGH N/A
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
CVE-1999-0547 2005-10-20 10.0 HIGH N/A
An SSH server allows authentication through the .rhosts file.
CVE-1999-0394 2005-10-20 10.0 HIGH N/A
DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.
CVE-2003-0565 2005-10-20 5.0 MEDIUM N/A
Multiple vulnerabilities in multiple vendor implementations of the X.400 protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an X.400 message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.
CVE-1999-0935 2005-05-02 10.0 HIGH N/A
classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.
CVE-1999-0936 2005-05-02 10.0 HIGH N/A
BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.
CVE-1999-0937 2005-05-02 10.0 HIGH N/A
BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.