
CVE-1999-0670
https://notcve.org/view.php?id=CVE-1999-0670
01 Sep 1999 — Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands. • http://ciac.llnl.gov/ciac/bulletins/j-064.shtml •

CVE-1999-0891 – Microsoft Internet Explorer 5 - Download Behaviour
https://notcve.org/view.php?id=CVE-1999-0891
01 Sep 1999 — The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect. • https://www.exploit-db.com/exploits/19530 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-1999-1016 – Microsoft Internet Explorer 5 - HTML Form Control Denial of Service
https://notcve.org/view.php?id=CVE-1999-1016
27 Aug 1999 — Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell. • https://www.exploit-db.com/exploits/19471 •

CVE-1999-1235 – Microsoft Internet Explorer 5 - FTP Password Storage
https://notcve.org/view.php?id=CVE-1999-1235
25 Aug 1999 — Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link. • https://www.exploit-db.com/exploits/19473 •

CVE-1999-0668 – Microsoft Internet Explorer 5 - ActiveX Object For Constructing Type Libraries For Scriptlets File Write
https://notcve.org/view.php?id=CVE-1999-0668
21 Aug 1999 — The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. • https://www.exploit-db.com/exploits/19468 •

CVE-1999-0802
https://notcve.org/view.php?id=CVE-1999-0802
27 May 1999 — Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ231450 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-1999-0917
https://notcve.org/view.php?id=CVE-1999-0917
27 May 1999 — The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ231452 •

CVE-1999-1367
https://notcve.org/view.php?id=CVE-1999-1367
06 May 1999 — Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users. • http://www.pcworld.com/news/article/0%2Caid%2C10842%2C00.asp •

CVE-1999-0487 – Microsoft Internet Explorer 4/5 - DHTML Edit ActiveX Control File Stealing / Cross Frame Access
https://notcve.org/view.php?id=CVE-1999-0487
01 May 1999 — The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files. • https://www.exploit-db.com/exploits/19094 •

CVE-1999-0488
https://notcve.org/view.php?id=CVE-1999-0488
21 Apr 1999 — Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability. • https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-012 •