CVE-1999-0600: A network intrusion detection system (IDS) does not verify the checksum on a packet.
A network intrusion detection system (IDS) does not verify the checksum on a packet.
Published Feb 4, 2000 · Updated Aug 1, 2024
Browse CVE records published in February 1999, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 312 matching CVEs · Page 3 of 7.
A network intrusion detection system (IDS) does not verify the checksum on a packet.
Published Feb 4, 2000 · Updated Aug 1, 2024
The rstat/rstatd service is running.
Published Feb 4, 2000 · Updated Aug 1, 2024
An SSH server allows authentication through the .rhosts file.
Published Feb 4, 2000 · Updated Aug 1, 2024
In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc.
Published Feb 4, 2000 · Updated Aug 1, 2024
A system does not present an appropriate legal message or warning to a user who is accessing it.
Published Feb 4, 2000 · Updated Aug 1, 2024
A system-critical Windows NT registry key has an inappropriate value.
Published Feb 4, 2000 · Updated Aug 1, 2024
An incorrect configuration of the Webcart CGI program could disclose private information.
Published Feb 4, 2000 · Updated Aug 1, 2024
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.
Published Feb 4, 2000 · Updated Aug 1, 2024
The daytime service is running.
Published Feb 4, 2000 · Updated Aug 1, 2024
The NT Alerter and Messenger services are running.
Published Feb 4, 2000 · Updated Aug 1, 2024
The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.
Published Feb 4, 2000 · Updated Aug 1, 2024
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.
Published Feb 4, 2000 · Updated Aug 1, 2024
The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.
Published Feb 4, 2000 · Updated Aug 1, 2024
The registry in Windows NT can be accessed remotely by users who are not administrators.
Published Feb 4, 2000 · Updated Aug 1, 2024
A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.
Published Feb 4, 2000 · Updated Aug 1, 2024
A system-critical Windows NT registry key has inappropriate permissions.
Published Feb 4, 2000 · Updated Aug 1, 2024
There is a one-way or two-way trust relationship between Windows NT domains.
Published Feb 4, 2000 · Updated Aug 1, 2024
A system is operating in "promiscuous" mode which allows it to perform packet sniffing.
Published Feb 4, 2000 · Updated Aug 1, 2024
An incorrect configuration of the Order Form 1.0 shopping cart CGI program could disclose private information.
Published Feb 4, 2000 · Updated Aug 1, 2024
A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.
Published Feb 4, 2000 · Updated Aug 1, 2024
A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.
Published Feb 4, 2000 · Updated Aug 1, 2024
The RPC portmapper service is running.
Published Feb 4, 2000 · Updated Aug 1, 2024
A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.
Published Feb 4, 2000 · Updated Aug 1, 2024
A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.
Published Feb 4, 2000 · Updated Aug 1, 2024
NFS exports system-critical data to the world, e.g. / or a password file.
Published Feb 4, 2000 · Updated Aug 1, 2024
A superfluous NFS server is running, but it is not importing or exporting any file systems.
Published Feb 4, 2000 · Updated Aug 1, 2024
A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.
Published Feb 4, 2000 · Updated Aug 1, 2024
A Windows NT log file has an inappropriate maximum size or retention period.
Published Feb 4, 2000 · Updated Aug 1, 2024
An incorrect configuration of the SoftCart CGI program "SoftCart.exe" could disclose private information.
Published Feb 4, 2000 · Updated Aug 1, 2024
An incorrect configuration of the WebStore 1.0 shopping cart CGI program "web_store.cgi" could disclose private information.
Published Feb 4, 2000 · Updated Aug 1, 2024
quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges.
Published Feb 4, 2000 · Updated Aug 1, 2024
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
Published Feb 4, 2000 · Updated Aug 1, 2024
The Logon box of a Windows NT system displays the name of the last user who logged in.
Published Feb 4, 2000 · Updated Aug 1, 2024
A Windows NT administrator account has the default name of Administrator.
Published Feb 4, 2000 · Updated Aug 1, 2024
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
Published Feb 4, 2000 · Updated Aug 1, 2024
A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking.
Published Feb 4, 2000 · Updated Aug 1, 2024
The ident/identd service is running.
Published Feb 4, 2000 · Updated Aug 1, 2024
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.
Published Feb 4, 2000 · Updated Aug 1, 2024
A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers.
Published Feb 4, 2000 · Updated Aug 1, 2024
A network service is running on a nonstandard port.
Published Feb 4, 2000 · Updated Aug 1, 2024
A router's routing tables can be obtained from arbitrary hosts.
Published Feb 4, 2000 · Updated Aug 1, 2024
A network intrusion detection system (IDS) does not properly reassemble fragmented packets.
Published Feb 4, 2000 · Updated Aug 1, 2024
An event log in Windows NT has inappropriate access permissions.
Published Feb 4, 2000 · Updated Aug 1, 2024
A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.
Published Feb 4, 2000 · Updated Aug 1, 2024
A Windows NT file system is not NTFS.
Published Feb 4, 2000 · Updated Aug 1, 2024
A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.
Published Feb 4, 2000 · Updated Aug 1, 2024
A system-critical Unix file or directory has inappropriate permissions.
Published Feb 4, 2000 · Updated Aug 1, 2024
A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.
Published Feb 4, 2000 · Updated Aug 1, 2024
rpc.admind in Solaris is not running in a secure mode.
Published Feb 4, 2000 · Updated Aug 1, 2024
IP forwarding is enabled on a machine which is not a router or firewall.
Published Feb 4, 2000 · Updated Aug 1, 2024