CVE catalog
Published CVEs with severity, CVSS and CISA KEV status. For Windows we also carry the part most catalogs leave blank: the update that fixes it, and the build revision that carries the fix.
395,855 CVEs · 1,723 known exploited · 2,982 Windows CVEs with a fix we can name
Oldest first.
| CVE | Severity | CVSS | Exploited | Fix | Published | Description |
|---|---|---|---|---|---|---|
| CVE-1999-0591 | High | 10 | - | - | 1999-01-01 | An event log in Windows NT has inappropriate access permissions. |
| CVE-1999-0589 | High | 10 | - | - | 1999-01-01 | A system-critical Windows NT registry key has inappropriate permissions. |
| CVE-1999-0588 | High | 7.5 | - | - | 1999-01-01 | A filter in a router or firewall allows unusual fragmented packets. |
| CVE-1999-0587 | High | 10 | - | - | 1999-01-01 | A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data. |
| CVE-1999-0586 | Low | 0 | - | - | 1999-01-01 | A network service is running on a nonstandard port. |
| CVE-1999-0584 | High | 10 | - | - | 1999-01-01 | A Windows NT file system is not NTFS. |
| CVE-1999-0583 | High | 10 | - | - | 1999-01-01 | There is a one-way or two-way trust relationship between Windows NT domains. |
| CVE-1999-0581 | High | 10 | - | - | 1999-01-01 | The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. |
| CVE-1999-0580 | High | 10 | - | - | 1999-01-01 | The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions. |
| CVE-1999-0579 | High | 10 | - | - | 1999-01-01 | A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. |
| CVE-1999-0578 | Medium | 4.6 | - | - | 1999-01-01 | A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. |
| CVE-1999-0577 | High | 10 | - | - | 1999-01-01 | A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. |
| CVE-1999-0571 | High | 10 | - | - | 1999-01-01 | A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts. |
| CVE-1999-0570 | High | 10 | - | - | 1999-01-01 | Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |
| CVE-1999-0569 | High | 10 | - | - | 1999-01-01 | A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. |
| CVE-1999-0568 | High | 10 | - | - | 1999-01-01 | rpc.admind in Solaris is not running in a secure mode. |
| CVE-1999-0565 | High | 10 | - | - | 1999-01-01 | A Sendmail alias allows input to be piped to a program. |
| CVE-1999-0564 | High | 10 | - | - | 1999-01-01 | An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled. |
| CVE-1999-0561 | High | 10 | - | - | 1999-01-01 | IIS has the #exec function enabled for Server Side Include (SSI) files. |
| CVE-1999-0560 | High | 10 | - | - | 1999-01-01 | A system-critical Windows NT file or directory has inappropriate permissions. |
| CVE-1999-0559 | High | 10 | - | - | 1999-01-01 | A system-critical Unix file or directory has inappropriate permissions. |
| CVE-1999-0556 | High | 10 | - | - | 1999-01-01 | Two or more Unix accounts have the same UID. |
| CVE-1999-0555 | High | 10 | - | - | 1999-01-01 | A Unix account with a name other than "root" has UID 0, i.e. root privileges. |
| CVE-1999-0554 | High | 10 | - | - | 1999-01-01 | NFS exports system-critical data to the world, e.g. / or a password file. |
| CVE-1999-0549 | High | 7.2 | - | - | 1999-01-01 | Windows NT automatically logs in an administrator upon rebooting. |
| CVE-1999-0548 | High | 10 | - | - | 1999-01-01 | A superfluous NFS server is running, but it is not importing or exporting any file systems. |
| CVE-1999-0547 | High | 10 | - | - | 1999-01-01 | An SSH server allows authentication through the .rhosts file. |
| CVE-1999-0539 | High | 10 | - | - | 1999-01-01 | A trust relationship exists between two Unix hosts. |
| CVE-1999-0531 | - | - | - | - | 1999-01-01 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "An SMTP servic... |
| CVE-1999-0530 | High | 10 | - | - | 1999-01-01 | A system is operating in "promiscuous" mode which allows it to perform packet sniffing. |
| CVE-1999-0529 | High | 7.5 | - | - | 1999-01-01 | A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc. |
| CVE-1999-0528 | High | 7.5 | - | - | 1999-01-01 | A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of. |
| CVE-1999-0527 | High | 10 | - | - | 1999-01-01 | The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten. |
| CVE-1999-0523 | Low | 0 | - | - | 1999-01-01 | ICMP echo (ping) is allowed from arbitrary hosts. |
| CVE-1999-0520 | Medium | 6.4 | - | - | 1999-01-01 | A system-critical NETBIOS/SMB share has inappropriate access control. |
| CVE-1999-0515 | High | 10 | - | - | 1999-01-01 | An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv. |
| CVE-1999-0512 | High | 10 | - | - | 1999-01-01 | A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers. |
| CVE-1999-0497 | Low | 0 | - | - | 1999-01-01 | Anonymous FTP is enabled. |
| CVE-1999-0495 | High | 10 | - | - | 1999-01-01 | A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares. |
| CVE-1999-0465 | High | 10 | - | - | 1999-01-01 | Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter. |
| CVE-1999-0454 | High | 10 | - | - | 1999-01-01 | A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso. |
| CVE-1999-0453 | Medium | 5 | - | - | 1999-01-01 | An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP). |
| CVE-1999-0452 | High | 10 | - | - | 1999-01-01 | A service or application has a backdoor password that was placed there by the developer. |
| CVE-1999-0448 | Medium | 5 | - | - | 1999-01-01 | IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. |
| CVE-1999-0401 | Low | 3.7 | - | - | 1999-01-01 | A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files. |
| CVE-1999-0399 | High | 7.5 | - | - | 1999-01-01 | The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands. |
| CVE-1999-0398 | Medium | 4.6 | - | - | 1999-01-01 | In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login. |
| CVE-1999-0397 | High | 10 | - | - | 1999-01-01 | The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext. |
| CVE-1999-0395 | Medium | 5.1 | - | - | 1999-01-01 | A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server. |
| CVE-1999-0394 | High | 10 | - | - | 1999-01-01 | DPEC Online Courseware allows an attacker to change another user's password without knowing the original password. |
What the Fix column means
A KB means we hold Microsoft's own remediation data for that CVE: the update that fixes it and, where Microsoft publishes one, the build revision that carries the fix. That is the difference between knowing a CVE exists and knowing whether the machine in front of you is still exposed to it.
If you want that answered for a specific machine rather than a specific CVE, paste your build into the patch checker. It walks the supersedence chain, so it can tell you that the update you actually installed covers a fix that shipped in an earlier one.
Where the data comes from
CVE records, CVSS scores and descriptions come from NVD. The exploited flag comes from CISA's KEV catalog. Windows fix data comes from Microsoft's own security update feed. We are not endorsed by or certified by any of them.