{"api_version":"1","generated_at":"2026-07-23T08:57:04+00:00","cve":"CVE-1999-1016","urls":{"html":"https://cve.report/CVE-1999-1016","api":"https://cve.report/api/cve/CVE-1999-1016.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-1999-1016","nvd":"https://nvd.nist.gov/vuln/detail/CVE-1999-1016"},"summary":{"title":"CVE-1999-1016","description":"Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.","state":"PUBLISHED","assigner":"mitre","published_at":"1999-08-27 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/606","name":"http://www.securityfocus.com/bid/606","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"Microsoft HTML Form Control DoS Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=ntbugtraq&m=93578772920970&w=2","name":"http://marc.info/?l=ntbugtraq&m=93578772920970&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'HTML code to crash IE5 and Outlook Express 5' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-1999-1016","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-1999-1016","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"1999","cve_id":"1016","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"frontpage","cpe6":"*","cpe7":"*","cpe8":"express","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"1999","cve_id":"1016","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"1999","cve_id":"1016","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"outlook_express","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"1999","cve_id":"1016","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"qualcomm","cpe5":"eudora","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-01T16:55:29.417Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"19990827 HTML code to crash IE5 and Outlook Express 5","tags":["mailing-list","x_refsource_NTBUGTRAQ","x_transferred"],"url":"http://marc.info/?l=ntbugtraq&m=93578772920970&w=2"},{"name":"606","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/606"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"1999-08-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"19990827 HTML code to crash IE5 and Outlook Express 5","tags":["mailing-list","x_refsource_NTBUGTRAQ"],"url":"http://marc.info/?l=ntbugtraq&m=93578772920970&w=2"},{"name":"606","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/606"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-1999-1016","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"19990827 HTML code to crash IE5 and Outlook Express 5","refsource":"NTBUGTRAQ","url":"http://marc.info/?l=ntbugtraq&m=93578772920970&w=2"},{"name":"606","refsource":"BID","url":"http://www.securityfocus.com/bid/606"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-1999-1016","datePublished":"2001-09-12T04:00:00.000Z","dateReserved":"2001-08-31T00:00:00.000Z","dateUpdated":"2024-08-01T16:55:29.417Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"1999-08-27 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:frontpage:*:*:express:*:*:*:*:*","matchCriteriaId":"39EC4E10-AE31-4F20-B04E-35A14F326EB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*","matchCriteriaId":"E6B8985B-B927-4928-B1DB-18E29F796992"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:outlook_express:5.0:*:*:*:*:*:*:*","matchCriteriaId":"1F71D6D7-6CB2-4BE9-839A-A5714144029C"},{"vulnerable":true,"criteria":"cpe:2.3:a:qualcomm:eudora:*:*:*:*:*:*:*:*","matchCriteriaId":"4E9BCC03-1C5A-4674-BE84-235B9225C074"}]}]}]},"legacy_mitre":{"record":{"CveYear":"1999","CveId":"1016","Ordinal":"1","Title":"CVE-1999-1016","CVE":"CVE-1999-1016","Year":"1999"},"notes":[{"CveYear":"1999","CveId":"1016","Ordinal":"1","NoteData":"Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.","Type":"Description","Title":"CVE-1999-1016"},{"CveYear":"1999","CveId":"1016","Ordinal":"2","NoteData":"2001-09-12","Type":"Other","Title":"Published"},{"CveYear":"1999","CveId":"1016","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}