
CVE-1999-0107 – Apache 1.2 - Denial of Service
https://notcve.org/view.php?id=CVE-1999-0107
30 Dec 1997 — Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters. • https://www.exploit-db.com/exploits/20558 •

CVE-1999-1125
https://notcve.org/view.php?id=CVE-1999-1125
19 Sep 1997 — Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file. • http://marc.info/?l=bugtraq&m=87602880019796&w=2 •

CVE-1999-0045 – Apache 1.1 / NCSA HTTPd 1.5.2 / Netscape Server 1.12/1.1/2.0 - a nph-test-cgi
https://notcve.org/view.php?id=CVE-1999-0045
10 Dec 1996 — List of arbitrary files on Web host via nph-test-cgi script. • https://www.exploit-db.com/exploits/19536 •

CVE-1999-0070 – Apache 0.8.x/1.0.x / NCSA HTTPd 1.x - 'test-cgi' Directory Listing
https://notcve.org/view.php?id=CVE-1999-0070
01 Apr 1996 — test-cgi program allows an attacker to list files on the server. • https://www.exploit-db.com/exploits/20435 •