{"api_version":"1","generated_at":"2026-06-21T03:07:16+00:00","cve":"CVE-1999-1380","urls":{"html":"https://cve.report/CVE-1999-1380","api":"https://cve.report/api/cve/CVE-1999-1380.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-1999-1380","nvd":"https://nvd.nist.gov/vuln/detail/CVE-1999-1380"},"summary":{"title":"CVE-1999-1380","description":"Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0.","state":"PUBLISHED","assigner":"mitre","published_at":"1997-05-04 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.1","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","baseScore":5.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://mlarchive.ima.com/win95/1997/May/0342.html","name":"http://mlarchive.ima.com/win95/1997/May/0342.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Windows 95 List May 1997 Archives: Norton/Microsoft Security Breach (Long) (fwd)","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/7188.php","name":"http://www.iss.net/security_center/static/7188.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database: nu-tuneocx-activex-control (7188): Norton Utilities for Windows 95 `tuneocx.ocx` ActiveX control could allow remote command execution","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://news.zdnet.co.uk/story/0%2C%2Cs2065518%2C00.html","name":"http://news.zdnet.co.uk/story/0%2C%2Cs2065518%2C00.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ZDNet |UK| - News - Story - ActiveX script for disaster highlights IE security flaw","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.net-security.sk/bugs/NT/nu20.html","name":"http://www.net-security.sk/bugs/NT/nu20.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"http://news.zdnet.co.uk/story/0,,s2065518,00.html","name":"MISC:http://news.zdnet.co.uk/story/0,,s2065518,00.html","refsource":"MITRE","tags":[],"title":"ZDNet |UK| - News - Story - ActiveX script for disaster highlights IE security flaw","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-1999-1380","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-1999-1380","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"1999","cve_id":"1380","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"norton_utilities","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-01T17:11:02.953Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://mlarchive.ima.com/win95/1997/May/0342.html"},{"name":"nu-tuneocx-activex-control(7188)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/7188.php"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://news.zdnet.co.uk/story/0%2C%2Cs2065518%2C00.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.net-security.sk/bugs/NT/nu20.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"1997-05-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-02-18T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://mlarchive.ima.com/win95/1997/May/0342.html"},{"name":"nu-tuneocx-activex-control(7188)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/7188.php"},{"tags":["x_refsource_MISC"],"url":"http://news.zdnet.co.uk/story/0%2C%2Cs2065518%2C00.html"},{"tags":["x_refsource_MISC"],"url":"http://www.net-security.sk/bugs/NT/nu20.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-1999-1380","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://mlarchive.ima.com/win95/1997/May/0342.html","refsource":"MISC","url":"http://mlarchive.ima.com/win95/1997/May/0342.html"},{"name":"nu-tuneocx-activex-control(7188)","refsource":"XF","url":"http://www.iss.net/security_center/static/7188.php"},{"name":"http://news.zdnet.co.uk/story/0,,s2065518,00.html","refsource":"MISC","url":"http://news.zdnet.co.uk/story/0,,s2065518,00.html"},{"name":"http://www.net-security.sk/bugs/NT/nu20.html","refsource":"MISC","url":"http://www.net-security.sk/bugs/NT/nu20.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-1999-1380","datePublished":"2002-03-09T05:00:00.000Z","dateReserved":"2001-08-31T00:00:00.000Z","dateUpdated":"2024-08-01T17:11:02.953Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"1997-05-04 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","baseScore":5.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":4.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:norton_utilities:2.0:*:*:*:*:*:*:*","matchCriteriaId":"9D0B5B84-4720-4EA2-AAF9-29D5D507514B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"1999","CveId":"1380","Ordinal":"1","Title":"CVE-1999-1380","CVE":"CVE-1999-1380","Year":"1999"},"notes":[{"CveYear":"1999","CveId":"1380","Ordinal":"1","NoteData":"Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0.","Type":"Description","Title":"CVE-1999-1380"},{"CveYear":"1999","CveId":"1380","Ordinal":"2","NoteData":"2002-03-09","Type":"Other","Title":"Published"},{"CveYear":"1999","CveId":"1380","Ordinal":"3","NoteData":"2002-02-17","Type":"Other","Title":"Modified"}]}}}