CVE-1999-1195
5.1 · MEDIUMOverview
CVE-1999-1195 is a medium-severity vulnerability affecting network_associates virusscan. It was published on May 5, 1999 and has a CVSS 2.0 base score of 5.1 (MEDIUM).
This vulnerability has a CVSS 2.0 base score of 5.1, rated MEDIUM. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.
Technical Description
NAI VirusScan NT 4.0.2 does not properly modify the scan.dat virus definition file during an update via FTP, but it reports that the update was successful, which could cause a system administrator to believe that the definitions have been updated correctly.
Remediation
Check the references section for vendor advisories and patches from network_associates. Update virusscan to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|
Frequently Asked Questions
What is CVE-1999-1195?
CVE-1999-1195 is a medium-severity vulnerability affecting network_associates virusscan. It was published on May 5, 1999 and has a CVSS 2.0 base score of 5.1 (MEDIUM).
How severe is CVE-1999-1195?
This vulnerability has a CVSS 2.0 base score of 5.1, rated MEDIUM. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.
How do I fix or remediate CVE-1999-1195?
Check the references section for vendor advisories and patches from network_associates. Update virusscan to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-1999-1195?
CyberStrike's AI-powered security agents can automatically detect CVE-1999-1195 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.
Related MEDIUM CVEs from 1999
View all →A system-critical NETBIOS/SMB share has inappropriate access control.
FTP PASV "Pizza Thief" denial of service and unauthorized data access. Attackers can steal data by
Denial of service in SMTP applications such as Sendmail, when a remote attacker (e.g. spammer) uses
talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Nets
NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another conn
NetBSD allows ARP packets to overwrite static ARP entries.
Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a
nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attack
Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent t
Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access rest
Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read