More free tools →

CVE catalog

Published CVEs with severity, CVSS and CISA KEV status. For Windows we also carry the part most catalogs leave blank: the update that fixes it, and the build revision that carries the fix.

395,855 CVEs · 1,721 known exploited · 2,982 Windows CVEs with a fix we can name

Oldest first.

CVESeverity CVSS Exploited Fix Published Description
CVE-1999-0958 High 7.2 - - 1998-01-12 sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.
CVE-1999-1045 High 7.8 - - 1998-01-15 pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.
CVE-1999-0271 Medium 5 - - 1998-01-15 Progressive Networks Real Video server (pnserver) can be crashed remotely.
CVE-1999-1487 High 7.2 - - 1998-01-21 Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.
CVE-1999-0014 High 7.2 - - 1998-01-21 Unauthorized privileged access or denial of service via dtappgather program in CDE.
CVE-1999-0013 High 8.4 - - 1998-01-22 Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.
CVE-1999-0125 Medium 4.6 - - 1998-01-25 Buffer overflow in SGI IRIX mailx program.
CVE-1999-0264 Medium 5 - - 1998-01-27 htmlscript CGI program allows remote read access to files.
CVE-1999-0486 Medium 5 - - 1998-02-01 Denial of service in AOL Instant Messenger when a remote attacker sends a malicious hyperlink to the receiving client, potentially causing a system crash.
CVE-1999-0305 Medium 5 - - 1998-02-01 The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.
CVE-1999-0304 High 7.2 - - 1998-02-01 mmap function in BSD allows local attackers in the kmem group to modify memory through devices.
CVE-1999-0296 High 7.2 - - 1998-02-01 Solaris volrmmount program allows attackers to read any file.
CVE-1999-0256 High 7.5 - - 1998-02-01 Buffer overflow in War FTP allows remote execution of commands.
CVE-1999-0087 Medium 5 - - 1998-02-01 Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.
CVE-1999-1445 Medium 5 - - 1998-02-02 Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.
CVE-1999-1269 Low 2.1 - - 1998-02-06 Screen savers in KDE beta 3 allows local users to overwrite arbitrary files via a symlink attack on the .kss.pid file.
CVE-1999-0012 High 7 - - 1998-02-06 Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
CVE-1999-0258 Medium 5 - - 1998-02-13 Bonk variation of teardrop IP fragmentation denial of service.
CVE-1999-0225 Medium 5 - - 1998-02-14 Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.
CVE-1999-1207 High 7.5 - - 1998-02-18 Buffer overflow in web-admin tool in NetXRay 2.6 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.
CVE-1999-1273 High 7.5 - - 1998-02-20 Squid Internet Object Cache 1.1.20 allows users to bypass access control lists (ACLs) by encoding the URL with hexadecimal escape sequences.
CVE-1999-0323 High 10 - - 1998-02-20 FreeBSD mmap function allows users to modify append-only or immutable files.
CVE-1999-0290 Medium 5 - - 1998-02-21 The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.
CVE-1999-1486 Low 1.2 - - 1998-02-25 sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.
CVE-1999-1229 Low 2.1 - - 1998-02-25 Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.
CVE-1999-1272 High 7.2 - - 1998-03-01 Buffer overflows in CDROM Confidence Test program (cdrom) allow local users to gain root privileges.
CVE-1999-0795 High 7.5 - - 1998-03-01 The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches.
CVE-1999-0514 Medium 5 - - 1998-03-01 UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target.
CVE-1999-0502 High 7.5 - - 1998-03-01 A Unix account has a default, null, blank, or missing password.
CVE-1999-0330 High 7.2 - - 1998-03-01 Linux bdash game has a buffer overflow that allows local users to gain root access.
CVE-1999-0320 High 9.3 - - 1998-03-01 SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.
CVE-1999-0266 High 7.5 - - 1998-03-01 The info2www CGI script allows remote file access or remote command execution.
CVE-1999-1407 Low 2.1 - - 1998-03-09 ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.
CVE-1999-1118 Low 2.1 - - 1998-03-11 ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters.
CVE-1999-0060 Medium 5 - - 1998-03-16 Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.
CVE-1999-1075 Medium 5 - - 1998-03-18 inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.
CVE-1999-0960 High 7.2 - - 1998-03-20 IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option.
CVE-1999-0551 Medium 4.6 - - 1998-04-01 HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests.
CVE-1999-0537 High 7.5 - - 1998-04-01 A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.
CVE-1999-0507 High 7.5 - - 1998-04-01 An account on a router, firewall, or other network device has a guessable password.
CVE-1999-0257 Medium 5 - - 1998-04-01 Nestea variation of teardrop IP fragmentation denial of service.
CVE-1999-0098 High 10 - - 1998-04-01 Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.
CVE-1999-0003 High 10 - - 1998-04-01 Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
CVE-1999-1183 High 7.6 - - 1998-04-02 System Manager sysmgr GUI in SGI IRIX 6.4 and 6.3 allows remote attackers to execute commands by providing a trojan horse (1) runtask or (2) runexec descriptor file, which is used to execute a System Manager Task when the user's Mailcap entry supports the x-sgi-task or x-sgi-exec type.
CVE-1999-0270 Medium 5 - - 1998-04-03 Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.
CVE-1999-1498 Low 3.6 - - 1998-04-06 Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.
CVE-1999-1505 High 7.5 - - 1998-04-07 Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via a long initial connect packet.
CVE-1999-1504 Medium 5 - - 1998-04-08 Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command.
CVE-1999-1503 Medium 5 - - 1998-04-08 Network Flight Recorder (NFR) 1.5 and 1.6 allows remote attackers to cause a denial of service in nfrd (crash) via a TCP packet with a null header and data field.
CVE-1999-1502 High 7.5 - - 1998-04-08 Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server name, (3) server address, or (4) argument to the map console command.

What the Fix column means

A KB means we hold Microsoft's own remediation data for that CVE: the update that fixes it and, where Microsoft publishes one, the build revision that carries the fix. That is the difference between knowing a CVE exists and knowing whether the machine in front of you is still exposed to it.

If you want that answered for a specific machine rather than a specific CVE, paste your build into the patch checker. It walks the supersedence chain, so it can tell you that the update you actually installed covers a fix that shipped in an earlier one.

Where the data comes from

CVE records, CVSS scores and descriptions come from NVD. The exploited flag comes from CISA's KEV catalog. Windows fix data comes from Microsoft's own security update feed. We are not endorsed by or certified by any of them.