CVE catalog
Published CVEs with severity, CVSS and CISA KEV status. For Windows we also carry the part most catalogs leave blank: the update that fixes it, and the build revision that carries the fix.
395,855 CVEs · 1,723 known exploited · 2,982 Windows CVEs with a fix we can name
Oldest first.
| CVE | Severity | CVSS | Exploited | Fix | Published | Description |
|---|---|---|---|---|---|---|
| CVE-1999-0653 | High | 10 | - | - | 1999-01-01 | A component service related to NIS+ is running. |
| CVE-1999-0652 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A database ser... |
| CVE-1999-0651 | High | 7.5 | - | - | 1999-01-01 | The rsh/rlogin service is running. |
| CVE-1999-0650 | Medium | 5 | - | - | 1999-01-01 | The netstat service is running, which provides sensitive information to remote attackers. |
| CVE-1999-0649 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The FSP servic... |
| CVE-1999-0648 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The X25 servic... |
| CVE-1999-0647 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The bootparam... |
| CVE-1999-0646 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The LDAP servi... |
| CVE-1999-0645 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The IRC servic... |
| CVE-1999-0644 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The NNTP news... |
| CVE-1999-0643 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The IMAP servi... |
| CVE-1999-0642 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A POP service... |
| CVE-1999-0641 | Low | 0 | - | - | 1999-01-01 | The UUCP service is running. |
| CVE-1999-0640 | High | 10 | - | - | 1999-01-01 | The Gopher service is running. |
| CVE-1999-0639 | Low | 0 | - | - | 1999-01-01 | The chargen service is running. |
| CVE-1999-0638 | Low | 0 | - | - | 1999-01-01 | The daytime service is running. |
| CVE-1999-0637 | Low | 0 | - | - | 1999-01-01 | The systat service is running. |
| CVE-1999-0636 | High | 10 | - | - | 1999-01-01 | The discard service is running. |
| CVE-1999-0635 | Low | 0 | - | - | 1999-01-01 | The echo service is running. |
| CVE-1999-0634 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SSH servic... |
| CVE-1999-0633 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The HTTP/WWW s... |
| CVE-1999-0632 | High | 7.3 | - | - | 1999-01-01 | The RPC portmapper service is running. |
| CVE-1999-0631 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The NFS servic... |
| CVE-1999-0630 | High | 10 | - | - | 1999-01-01 | The NT Alerter and Messenger services are running. |
| CVE-1999-0629 | Low | 0 | - | - | 1999-01-01 | The ident/identd service is running. |
| CVE-1999-0625 | Low | 0 | - | - | 1999-01-01 | The rpc.rquotad service is running. |
| CVE-1999-0624 | Low | 0 | - | - | 1999-01-01 | The rstat/rstatd service is running. |
| CVE-1999-0623 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The X Windows... |
| CVE-1999-0622 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A component se... |
| CVE-1999-0621 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A component se... |
| CVE-1999-0620 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A component se... |
| CVE-1999-0619 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The Telnet ser... |
| CVE-1999-0618 | High | 10 | - | - | 1999-01-01 | The rexec service is running. |
| CVE-1999-0617 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SMTP servi... |
| CVE-1999-0616 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The TFTP servi... |
| CVE-1999-0615 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SNMP servi... |
| CVE-1999-0614 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The FTP servic... |
| CVE-1999-0613 | Low | 0 | - | - | 1999-01-01 | The rpc.sprayd service is running. |
| CVE-1999-0611 | High | 10 | - | - | 1999-01-01 | A system-critical Windows NT registry key has an inappropriate value. |
| CVE-1999-0603 | High | 10 | - | - | 1999-01-01 | In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc. |
| CVE-1999-0602 | High | 10 | - | - | 1999-01-01 | A network intrusion detection system (IDS) does not properly reassemble fragmented packets. |
| CVE-1999-0601 | High | 10 | - | - | 1999-01-01 | A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets. |
| CVE-1999-0600 | High | 10 | - | - | 1999-01-01 | A network intrusion detection system (IDS) does not verify the checksum on a packet. |
| CVE-1999-0599 | High | 10 | - | - | 1999-01-01 | A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers. |
| CVE-1999-0598 | High | 10 | - | - | 1999-01-01 | A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection. |
| CVE-1999-0597 | High | 10 | - | - | 1999-01-01 | A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire. |
| CVE-1999-0596 | High | 10 | - | - | 1999-01-01 | A Windows NT log file has an inappropriate maximum size or retention period. |
| CVE-1999-0594 | High | 10 | - | - | 1999-01-01 | A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive. |
| CVE-1999-0593 | Medium | 4.9 | - | - | 1999-01-01 | The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. |
| CVE-1999-0592 | High | 10 | - | - | 1999-01-01 | The Logon box of a Windows NT system displays the name of the last user who logged in. |
What the Fix column means
A KB means we hold Microsoft's own remediation data for that CVE: the update that fixes it and, where Microsoft publishes one, the build revision that carries the fix. That is the difference between knowing a CVE exists and knowing whether the machine in front of you is still exposed to it.
If you want that answered for a specific machine rather than a specific CVE, paste your build into the patch checker. It walks the supersedence chain, so it can tell you that the update you actually installed covers a fix that shipped in an earlier one.
Where the data comes from
CVE records, CVSS scores and descriptions come from NVD. The exploited flag comes from CISA's KEV catalog. Windows fix data comes from Microsoft's own security update feed. We are not endorsed by or certified by any of them.