Vulnerabilities (CVE)

Filtered by CWE-16
Total 270 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-2247 1 Mambo 1 Mambo Site Server 2026-06-16 5.0 MEDIUM N/A
The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.
CVE-2002-2234 1 Netscreen 1 Screenos 2026-06-16 4.3 MEDIUM N/A
NetScreen ScreenOS before 4.0.1 allows remote attackers to bypass the Malicious-URL blocking feature by splitting the URL into fragmented IP requests.
CVE-2000-1247 1 Apache 1 Jserv 2026-06-16 2.1 LOW N/A
The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.
CVE-1999-0886 1 Microsoft 1 Windows Nt 2026-06-16 9.0 HIGH N/A
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
CVE-1999-0875 2 Microsoft, Sun 5 Windows 2000, Windows 95, Windows 98se and 2 more 2026-06-16 7.5 HIGH N/A
DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
CVE-1999-0858 1 Microsoft 1 Internet Explorer 2026-06-16 5.0 MEDIUM N/A
Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.
CVE-1999-0766 1 Microsoft 2 Internet Explorer, Java Virtual Machine 2026-06-16 9.3 HIGH N/A
The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.
CVE-1999-0725 1 Microsoft 1 Internet Information Server 2026-06-16 7.1 HIGH N/A
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
CVE-1999-0701 1 Microsoft 1 Windows Nt 2026-06-16 7.2 HIGH N/A
After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.
CVE-1999-0656 1 Linux 1 Linux Kernel 2026-06-16 5.0 MEDIUM N/A
The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.