CVE-1999-1440
https://notcve.org/view.php?id=CVE-1999-1440
Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client. • http://marc.info/?l=bugtraq&m=91522424302962&w=2 http://www.securityfocus.com/bid/132 •
CVE-1999-1289
https://notcve.org/view.php?id=CVE-1999-1289
ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration. • http://www.securityfocus.com/archive/1/11233 https://exchange.xforce.ibmcloud.com/vulnerabilities/1398 •