CVE catalog
Published CVEs with severity, CVSS and CISA KEV status. For Windows we also carry the part most catalogs leave blank: the update that fixes it, and the build revision that carries the fix.
395,855 CVEs · 1,723 known exploited · 2,982 Windows CVEs with a fix we can name
Oldest first.
| CVE | Severity | CVSS | Exploited | Fix | Published | Description |
|---|---|---|---|---|---|---|
| CVE-2000-0367 | High | 7.2 | - | - | 1999-02-18 | Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges. |
| CVE-1999-1495 | Low | 2.1 | - | - | 1999-02-18 | xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file. |
| CVE-1999-0405 | High | 7.2 | - | - | 1999-02-18 | A buffer overflow in lsof allows local users to obtain root privilege. |
| CVE-1999-1482 | High | 7.2 | - | - | 1999-02-19 | SVGAlib zgv 3.0-7 and earlier allows local users to gain root access via a privilege leak of the iopl(3) privileges to child processes. |
| CVE-1999-1372 | Medium | 4.6 | - | - | 1999-02-19 | Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges. |
| CVE-1999-1255 | Medium | 5 | - | - | 1999-02-19 | Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter. |
| CVE-1999-1101 | Medium | 4.6 | - | - | 1999-02-19 | Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users to easily decrypt the passwords and gain privileges. |
| CVE-1999-0485 | Low | 2.6 | - | - | 1999-02-19 | Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD. |
| CVE-1999-0460 | Low | 2.1 | - | - | 1999-02-19 | Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service. |
| CVE-1999-0412 | High | 7.5 | - | - | 1999-02-19 | In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. |
| CVE-1999-0406 | High | 7.2 | - | - | 1999-02-19 | Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege. |
| CVE-1999-1168 | High | 7.2 | - | - | 1999-02-20 | install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of arbitrary files via a symlink attack on a temporary file. |
| CVE-1999-0376 | Medium | 4.6 | - | - | 1999-02-20 | Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. |
| CVE-1999-1049 | High | 10 | - | - | 1999-02-21 | ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password. |
| CVE-1999-0441 | Medium | 5 | - | - | 1999-02-22 | Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service. |
| CVE-1999-0379 | High | 7.5 | - | - | 1999-02-22 | Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting. |
| CVE-1999-0378 | Medium | 5 | - | - | 1999-02-22 | InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands. |
| CVE-1999-0377 | Medium | 5 | - | - | 1999-02-22 | Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services. |
| CVE-1999-0484 | Low | 2.1 | - | - | 1999-02-23 | Buffer overflow in OpenBSD ping. |
| CVE-1999-1247 | High | 7.2 | - | - | 1999-02-24 | Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges. |
| CVE-1999-0483 | Low | 2.1 | - | - | 1999-02-25 | OpenBSD crash using nlink value in FFS and EXT2FS filesystems. |
| CVE-1999-0408 | High | 10 | - | - | 1999-02-25 | Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server. |
| CVE-1999-0380 | Medium | 4.6 | - | - | 1999-02-25 | SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user. |
| CVE-1999-0381 | High | 7.2 | - | - | 1999-02-26 | super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access. |
| CVE-2000-0371 | Low | 1.2 | - | - | 1999-03-01 | The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack. |
| CVE-1999-1046 | High | 10 | - | - | 1999-03-01 | Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181. |
| CVE-1999-0479 | Medium | 5 | - | - | 1999-03-01 | Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems. |
| CVE-1999-0476 | High | 7.2 | - | - | 1999-03-01 | A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user. |
| CVE-1999-0440 | High | 7.5 | - | - | 1999-03-01 | The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages. |
| CVE-1999-0438 | Medium | 5 | - | - | 1999-03-01 | Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address. |
| CVE-1999-0437 | Medium | 5 | - | - | 1999-03-01 | Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port. |
| CVE-1999-0436 | Medium | 4.6 | - | - | 1999-03-01 | Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges. |
| CVE-1999-0435 | High | 7.2 | - | - | 1999-03-01 | MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM. |
| CVE-1999-0432 | Medium | 4.6 | - | - | 1999-03-01 | ftp on HP-UX 11.00 allows local users to gain privileges. |
| CVE-1999-0431 | Medium | 5 | - | - | 1999-03-01 | Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service. |
| CVE-1999-0430 | Medium | 5 | - | - | 1999-03-01 | Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload. |
| CVE-1999-0429 | High | 7.5 | - | - | 1999-03-01 | The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference. |
| CVE-1999-0426 | Critical | 9.8 | - | - | 1999-03-01 | The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing. |
| CVE-1999-0419 | Medium | 5 | - | - | 1999-03-01 | When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service. |
| CVE-1999-0414 | Medium | 5 | - | - | 1999-03-01 | In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection. |
| CVE-1999-0413 | High | 7.2 | - | - | 1999-03-01 | A buffer overflow in the SGI X server allows local users to gain root access through the X server font path. |
| CVE-1999-0386 | Medium | 5 | - | - | 1999-03-01 | Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL. |
| CVE-1999-0261 | Medium | 5 | - | - | 1999-03-01 | Netmanager Chameleon SMTPd has several buffer overflows that cause a crash. |
| CVE-1999-0223 | Low | 2.1 | - | - | 1999-03-01 | Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry. |
| CVE-1999-0222 | Medium | 5 | - | - | 1999-03-01 | Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL. |
| CVE-1999-0221 | Medium | 5 | - | - | 1999-03-01 | Denial of service of Ascend routers through port 150 (remote administration). |
| CVE-1999-1551 | Medium | 5 | - | - | 1999-03-02 | Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL. |
| CVE-2000-0019 | Low | 2.1 | - | - | 1999-03-04 | IMail POP3 daemon uses weak encryption, which allows local users to read files. |
| CVE-1999-1256 | Medium | 4.6 | - | - | 1999-03-04 | Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which allows local users to obtain the password from that file. |
| CVE-1999-0409 | Medium | 4.6 | - | - | 1999-03-04 | Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access. |
What the Fix column means
A KB means we hold Microsoft's own remediation data for that CVE: the update that fixes it and, where Microsoft publishes one, the build revision that carries the fix. That is the difference between knowing a CVE exists and knowing whether the machine in front of you is still exposed to it.
If you want that answered for a specific machine rather than a specific CVE, paste your build into the patch checker. It walks the supersedence chain, so it can tell you that the update you actually installed covers a fix that shipped in an earlier one.
Where the data comes from
CVE records, CVSS scores and descriptions come from NVD. The exploited flag comes from CISA's KEV catalog. Windows fix data comes from Microsoft's own security update feed. We are not endorsed by or certified by any of them.