Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
1999-12-31 CVE-1999-1233 Unspecified vulnerability in Microsoft Internet Information Server 4.0
IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.
network
low complexity
microsoft
7.5
1999-12-31 CVE-1999-1223 Unspecified vulnerability in Microsoft Internet Information Server 3.0
IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-1222 Unspecified vulnerability in Microsoft Windows NT 4.0
Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-1206 Unspecified vulnerability in Systemsoft Systemwizard
SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control.
network
low complexity
systemsoft
7.5
1999-12-31 CVE-1999-1177 Unspecified vulnerability in Lincoln D. Stein Nph-Publish
Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a ..
network
low complexity
lincoln-d-stein
5.0
1999-12-31 CVE-1999-1175 Unspecified vulnerability in Cisco IOS
Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.
network
low complexity
cisco
7.5
1999-12-31 CVE-1999-1157 Denial-Of-Service vulnerability in Windows NT
Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-1148 Unspecified vulnerability in Microsoft Internet Information Server
FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-1132 Unspecified vulnerability in Microsoft Windows NT 4.0
Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-1127 Missing Release of Resource after Effective Lifetime vulnerability in Microsoft Windows NT 4.0
Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.
network
low complexity
microsoft CWE-772
7.5