More free tools →

CVE catalog

Published CVEs with severity, CVSS and CISA KEV status. For Windows we also carry the part most catalogs leave blank: the update that fixes it, and the build revision that carries the fix.

395,855 CVEs · 1,723 known exploited · 2,982 Windows CVEs with a fix we can name

Oldest first.

CVESeverity CVSS Exploited Fix Published Description
CVE-1999-0393 Medium 5 - - 1999-01-01 Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
CVE-1999-0388 Medium 4.6 - - 1999-01-01 DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.
CVE-1999-0384 Medium 4.6 - - 1999-01-01 The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.
CVE-1999-0364 High 10 - - 1999-01-01 Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
CVE-1999-0361 High 10 - - 1999-01-01 NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.
CVE-1999-0355 Medium 5 - - 1999-01-01 Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.
CVE-1999-0286 High 10 - - 1999-01-01 In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.
CVE-1999-0285 High 10 - - 1999-01-01 Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
CVE-1999-0283 High 10 - - 1999-01-01 The Java Web Server would allow remote users to obtain the source code for CGI programs.
CVE-1999-0276 High 7.5 - - 1999-01-01 mSQL v2.0.1 and below allows remote execution through a buffer overflow.
CVE-1999-0268 High 10 - - 1999-01-01 MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.
CVE-1999-0255 High 10 - - 1999-01-01 Buffer overflow in ircd allows arbitrary command execution.
CVE-1999-0248 High 10 - - 1999-01-01 A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.
CVE-1999-0243 High 10 - - 1999-01-01 Linux cfingerd could be exploited to gain root access.
CVE-1999-0240 High 7.5 - - 1999-01-01 Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.
CVE-1999-0231 Medium 5 - - 1999-01-01 Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.
CVE-1999-0226 High 10 - - 1999-01-01 Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
CVE-1999-0220 High 10 - - 1999-01-01 Attackers can do a denial of service of IRC by crashing the server.
CVE-1999-0205 Medium 5 - - 1999-01-01 Denial of service in Sendmail 8.6.11 and 8.6.12.
CVE-1999-0200 High 10 - - 1999-01-01 Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.
CVE-1999-0198 High 10 - - 1999-01-01 finger .@host on some systems may print information on some user accounts.
CVE-1999-0197 High 10 - - 1999-01-01 finger 0@host on some systems may print information on some user accounts.
CVE-1999-0187 - - - - 1999-01-01 Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0022. Reason: This candidate is a duplicate of CVE-1999-0022. Notes: All CVE users should reference CVE-1999-0022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
CVE-1999-0110 - - - - 1999-01-01 Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0315. Reason: This candidate's original description had a typo that delayed it from being detected as a duplicate of CVE-1999-0315. Notes: All CVE users should reference CVE-1999-0315 instead of this candidate. All references and descriptions i...
CVE-1999-0020 - - - - 1999-01-01 Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0032. Reason: This candidate is a duplicate of CVE-1999-0032. Notes: All CVE users should reference CVE-1999-0032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
CVE-2000-0005 High 7.2 - - 1999-01-02 HP-UX aserver program allows local users to gain privileges via a symlink attack.
CVE-1999-1422 High 7.2 - - 1999-01-02 The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.
CVE-1999-1170 Medium 4.6 - - 1999-01-02 IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.
CVE-1999-0402 Medium 5 - - 1999-01-02 wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
CVE-2000-0054 Medium 5 - - 1999-01-03 search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack.
CVE-1999-0914 High 7.2 - - 1999-01-03 Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.
CVE-1999-0389 High 7.2 - - 1999-01-03 Buffer overflow in the bootp server in the Debian Linux netstd package.
CVE-1999-0464 Low 2.1 - - 1999-01-04 Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.
CVE-1999-0390 High 7.2 - - 1999-01-04 Buffer overflow in Dosemu Slang library in Linux.
CVE-1999-0391 High 7.5 - - 1999-01-05 The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.
CVE-1999-1268 High 7.2 - - 1999-01-06 Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.
CVE-1999-0458 Low 2.1 - - 1999-01-06 L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.
CVE-1999-0442 Low 2.1 - - 1999-01-07 Solaris ff.core allows local users to modify files.
CVE-1999-0392 Medium 5 - - 1999-01-10 Buffer overflow in Thomas Boutell's cgic library version up to 1.05.
CVE-1999-0063 Medium 5 - - 1999-01-11 Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.
CVE-1999-1538 Low 2.1 - - 1999-01-14 When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.
CVE-1999-1376 High 10 - - 1999-01-14 Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.
CVE-1999-1172 Medium 5 - - 1999-01-14 By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.
CVE-1999-0678 Medium 5 - - 1999-01-17 A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.
CVE-1999-0457 High 7.2 - - 1999-01-17 Linux ftpwatch program allows local users to gain root privileges.
CVE-1999-0451 Low 2.1 - - 1999-01-19 Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.
CVE-1999-0119 High 10 - - 1999-01-19 Windows NT 4.0 beta allows users to read and delete shares.
CVE-1999-1264 High 7.5 - - 1999-01-21 WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been explicitly disabled.
CVE-1999-0121 High 7.2 - - 1999-01-21 Buffer overflow in dtaction command gives root access.
CVE-1999-1544 Medium 5 - - 1999-01-24 Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.

What the Fix column means

A KB means we hold Microsoft's own remediation data for that CVE: the update that fixes it and, where Microsoft publishes one, the build revision that carries the fix. That is the difference between knowing a CVE exists and knowing whether the machine in front of you is still exposed to it.

If you want that answered for a specific machine rather than a specific CVE, paste your build into the patch checker. It walks the supersedence chain, so it can tell you that the update you actually installed covers a fix that shipped in an earlier one.

Where the data comes from

CVE records, CVSS scores and descriptions come from NVD. The exploited flag comes from CISA's KEV catalog. Windows fix data comes from Microsoft's own security update feed. We are not endorsed by or certified by any of them.