CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
521 | CVE-1999-0524 | Candidate | ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. | Modified (20161206) | MODIFY(3) Baker, Frech, Meunier | REJECT(1) Northcutt | Frech> XF:icmp-timestamp | XF:icmp-netmask | Meunier> If this is not merged with 1999-0523 as I commented for that | CVE, then the description should be changed to "ICMP messages of types | 13 and 14 (timestamp request and reply) and 17 and 18 (netmask request | and reply) are acted upon without any access control". It"s a more | precise and correct language. I believe that this is a valid CVE | entry (it"s a common source of vulnerabilities or exposures) even | though I see that the inferred action was "reject". Knowing the time | of a host also allows attacks against random number generators that | are seeded with the current time. I want to push to have it accepted. | Baker> I agree with the description changes suggested by Pascal | View |
522 | CVE-1999-0525 | Candidate | IP traceroute is allowed from arbitrary hosts. | Proposed (19990726) | MODIFY(1) Frech | NOOP(1) Baker | REJECT(1) Northcutt | Frech> XF:traceroute | View |
523 | CVE-1999-0526 | Entry | An X server"s access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server. | View | |||
524 | CVE-1999-0527 | Candidate | The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten. | Proposed (19990803) | ACCEPT(3) Baker, Northcutt, Wall | MODIFY(1) Frech | Northcutt> That that starts to get specific :) | Frech> ftp-writable-directory(6253) | ftp-write(53) | "writeable" in the description should be "writable." | View |
525 | CVE-1999-0528 | Candidate | A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of. | Proposed (19990726) | ACCEPT(3) Baker, Meunier, Northcutt | MODIFY(1) Frech | Frech> possibly XF:nisd-dns-fwd-check | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:firewall-external-packet-forwarding(8372) | View |
Page 105 of 20943, showing 5 records out of 104715 total, starting on record 521, ending on 525