{"id":"CVE-1999-1099","title":"Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.","summary":"Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.","severity":"medium","cvss":5,"cvssVector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","published":"1996-11-22","updated":"2026-06-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-1999-1099","references":[{"url":"http://marc.info/?l=bugtraq&m=87602167420184&w=2","label":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65","label":"cve@mitre.org"},{"url":"http://marc.info/?l=bugtraq&m=87602167420184&w=2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01309,"epssPercentile":0.689,"ingestedAt":"2026-06-22T15:59:08.127Z","slug":"CVE-1999-1099","body":"## Overview\n\nKerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}