-
CVE-1999-0509
•
published on February 4, 2000
Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.
-
CVE-1999-0519
•
published on February 4, 2000
A NETBIOS/SMB share password is the default, null, or missing.
-
CVE-1999-0521
•
published on February 4, 2000
An NIS domain name is easily guessable.
-
CVE-1999-0523
•
published on February 4, 2000
ICMP echo (ping) is allowed from arbitrary hosts.
-
CVE-1999-0528
•
published on February 4, 2000
A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.
-
CVE-1999-0529
•
published on February 4, 2000
A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.
-
CVE-1999-0629
•
published on February 4, 2000
The ident/identd service is running.
-
CVE-1999-0630
•
published on February 4, 2000
The NT Alerter and Messenger services are running.
-
CVE-1999-0639
•
published on February 4, 2000
The chargen service is running.
-
CVE-1999-0654
•
published on February 4, 2000
The OS/2 or POSIX subsystem in NT is enabled.
-
CVE-1999-0667
•
published on February 4, 2000
The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.
-
CVE-1999-0673
•
published on February 4, 2000
Buffer overflow in ALMail32 POP3 client via From: or To: headers.
-
CVE-1999-0533
•
published on February 4, 2000
A DNS server allows inverse queries.
-
CVE-1999-0546
•
published on February 4, 2000
The Windows NT guest account is enabled.
-
CVE-1999-0548
•
published on February 4, 2000
A superfluous NFS server is running, but it is not importing or exporting any file systems.
-
CVE-1999-0549
•
published on February 4, 2000
Windows NT automatically logs in an administrator upon rebooting.
-
CVE-1999-0561
•
published on February 4, 2000
IIS has the #exec function enabled for Server Side Include (SSI) files.
-
CVE-1999-0570
•
published on February 4, 2000
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
-
CVE-1999-0590
•
published on February 4, 2000
A system does not present an appropriate legal message or warning to a user who is accessing it.
-
CVE-1999-0597
•
published on February 4, 2000
A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.