CVE Database - 1999

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

14
Matching CVEs
15853
Critical
26962
High
69389
High WAF Coverage

CVE-1999-0001

MEDIUM
5.00 CVSS 2.0

ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.

Improper Input Validation
WAF: Medium

CVE-1999-0995

HIGH
7.80 CVSS 2.0

Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request."

Improper Input Validation
WAF: Medium

CVE-1999-1547

HIGH
7.50 CVSS 2.0

Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent.

Improper Input Validation
WAF: Medium

CVE-1999-0999

MEDIUM
4.30 CVSS 2.0

Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.

Improper Input Validation
WAF: Medium

CVE-1999-0987

HIGH
10.00 CVSS 2.0

Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.

Improper Authentication
WAF: Low

CVE-1999-0702

HIGH
10.00 CVSS 2.0

Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.

Code Injection
WAF: Medium

CVE-1999-0891

MEDIUM
5.00 CVSS 2.0

The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.

Code Injection
WAF: Medium

CVE-1999-0867

MEDIUM
5.00 CVSS 2.0

Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.

Improper Input Validation
WAF: Medium

CVE-1999-0680

MEDIUM
5.00 CVSS 2.0

Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.

Improper Authentication
WAF: Low

CVE-1999-0721

HIGH
7.80 CVSS 2.0

Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.

Improper Input Validation
WAF: Medium

CVE-1999-0918

HIGH
7.80 CVSS 2.0

Denial of service in various Windows systems via malformed, fragmented IGMP packets.

Improper Input Validation
WAF: Medium

CVE-1999-0726

HIGH
7.80 CVSS 2.0

An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.

Improper Input Validation
WAF: Medium

CVE-1999-0491

MEDIUM
4.60 CVSS 2.0

The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.

Code Injection
WAF: Medium

CVE-1999-0366

HIGH
7.50 CVSS 2.0

In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.

Improper Authentication
WAF: Low