CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
330 | CVE-1999-0331 | Candidate | Buffer overflow in Internet Explorer 4.0(1). | Modified (20040811) | ACCEPT(2) Baker, Northcutt | MODIFY(2) Frech, Shostack | RECAST(1) Prosser | REJECT(2) Christey, LeBlanc | Shostack> this is a high cardinality item | Prosser> needs to be more specific. | Frech> Replace reference with XF:iemk-bug (msie-bo is obsolete and a vague | duplicate) | Description (from xfdb): Some versions of Internet Explorer for Windows | contain a vulnerability that may crash the broswer when a malicious web site | contains a certain kind of URL (that begins with "mk://") with more | characters than the browser supports. | Christey> The description is too vague. | LeBlanc> too vague | Christey> Add period to the end of the description. | View |
163 | CVE-1999-0163 | Candidate | In older versions of Sendmail, an attacker could use a pipe character to execute root commands. | Proposed (19990714) | ACCEPT(2) Frech, Northcutt | MODIFY(1) Prosser | NOOP(2) Baker, Christey | RECAST(1) Shostack | Shostack> there was a "To: |" and a "From: |" attack, which I | think are seperate. | Prosser> older vulnerability, but one additional reference is- | The Ultimate Sendmail Hole List by Markus H・ner @ | bau2.uibk.ac.at/matic/buglist.htm | "|PROGRAM " | Christey> Description needs to be more specific to distinguish between | this and CVE-1999-0203, as alluded to by Adam Shostack | View |
512 | CVE-1999-0515 | Candidate | An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv. | Proposed (19990728) | ACCEPT(2) Baker, Northcutt | MODIFY(1) Frech | REJECT(1) Shostack | Shostack> Overly broad | Frech> XF:rsh-equiv(111) | Baker> Since this is unrestricted trust, I agree this is a problem | View |
165 | CVE-1999-0165 | Candidate | NFS cache poisoning. | Modified (20040811) | ACCEPT(3) Baker, Frech, Northcutt | MODIFY(1) Shostack | NOOP(1) Prosser | REVIEWING(1) Christey | Shostack> need more data | Christey> need more refs | Christey> Add period to the end of the description. | View |
568 | CVE-1999-0586 | Candidate | A network service is running on a nonstandard port. | Proposed (19990728) | NOOP(1) Baker | RECAST(1) Shostack | REJECT(1) Northcutt | Shostack> Might be acceptable if clearer; is that a standard service on a | non-standard port, or any service on an unassigned port? | Baker> It might actually be an enhancement rather than a problem to run a service on a non-standard port | View |
Page 14 of 20943, showing 5 records out of 104715 total, starting on record 66, ending on 70