{"api_version":"1","generated_at":"2026-07-23T12:08:22+00:00","cve":"CVE-1999-1167","urls":{"html":"https://cve.report/CVE-1999-1167","api":"https://cve.report/api/cve/CVE-1999-1167.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-1999-1167","nvd":"https://nvd.nist.gov/vuln/detail/CVE-1999-1167"},"summary":{"title":"CVE-1999-1167","description":"Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.","state":"PUBLISHED","assigner":"mitre","published_at":"1999-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.wired.com/news/technology/0%2C1282%2C20636%2C00.html","name":"http://www.wired.com/news/technology/0%2C1282%2C20636%2C00.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Third Voice Rips Holes in Web","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.wired.com/news/technology/0%2C1282%2C20677%2C00.html","name":"http://www.wired.com/news/technology/0%2C1282%2C20677%2C00.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Third Voice Patches Holes","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/7252.php","name":"http://www.iss.net/security_center/static/7252.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database:","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.wired.com/news/technology/0,1282,20677,00.html","name":"CONFIRM:http://www.wired.com/news/technology/0,1282,20677,00.html","refsource":"MITRE","tags":[],"title":"Third Voice Patches Holes","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.wired.com/news/technology/0,1282,20636,00.html","name":"MISC:http://www.wired.com/news/technology/0,1282,20636,00.html","refsource":"MITRE","tags":[],"title":"Third Voice Rips Holes in Web","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-1999-1167","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-1999-1167","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"1999","cve_id":"1167","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"third_voice","cpe5":"third_voice_web","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-01T17:02:53.789Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"thirdvoice-cross-site-scripting(7252)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/7252.php"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.wired.com/news/technology/0%2C1282%2C20636%2C00.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.wired.com/news/technology/0%2C1282%2C20677%2C00.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"1999-07-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-02-20T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"thirdvoice-cross-site-scripting(7252)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/7252.php"},{"tags":["x_refsource_MISC"],"url":"http://www.wired.com/news/technology/0%2C1282%2C20636%2C00.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.wired.com/news/technology/0%2C1282%2C20677%2C00.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-1999-1167","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"thirdvoice-cross-site-scripting(7252)","refsource":"XF","url":"http://www.iss.net/security_center/static/7252.php"},{"name":"http://www.wired.com/news/technology/0,1282,20636,00.html","refsource":"MISC","url":"http://www.wired.com/news/technology/0,1282,20636,00.html"},{"name":"http://www.wired.com/news/technology/0,1282,20677,00.html","refsource":"CONFIRM","url":"http://www.wired.com/news/technology/0,1282,20677,00.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-1999-1167","datePublished":"2002-03-09T05:00:00.000Z","dateReserved":"2001-08-31T00:00:00.000Z","dateUpdated":"2024-08-01T17:02:53.789Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"1999-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:third_voice:third_voice_web:*:*:*:*:*:*:*:*","matchCriteriaId":"39EAEEEC-D079-4F30-AA71-F021D48F14C0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"1999","CveId":"1167","Ordinal":"1","Title":"CVE-1999-1167","CVE":"CVE-1999-1167","Year":"1999"},"notes":[{"CveYear":"1999","CveId":"1167","Ordinal":"1","NoteData":"Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.","Type":"Description","Title":"CVE-1999-1167"},{"CveYear":"1999","CveId":"1167","Ordinal":"2","NoteData":"2002-03-09","Type":"Other","Title":"Published"},{"CveYear":"1999","CveId":"1167","Ordinal":"3","NoteData":"2002-02-20","Type":"Other","Title":"Modified"}]}}}