CVE List

Id CVE No. Status Description Phase Votes Comments Actions
986  CVE-1999-1006  Candidate  Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.  Proposed (19991222)  ACCEPT(4) Baker, Cole, Prosser, Stracener | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:groupwise-web-path | Prosser> Pretty well confirmed by testing with responses to BugTraq list. | | additional ref: BugTraq ID 879 http://www.securityfocus.com/bid/879 | Christey> A later discovery almost 2 years later is at: | BUGTRAQ:20020227 SecurityOffice Security Advisory:// Novell | GroupWise Web Access Path Disclosure Vulnerability | http://marc.theaimsgroup.com/?l=bugtraq&m=101494830315071&w=2 | CD:SF-LOC might suggest merging these together.  View
987  CVE-1999-1007  Entry  Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.        View
988  CVE-1999-1008  Entry  xsoldier program allows local users to gain root access via a long argument.        View
989  CVE-1999-1009  Candidate  The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user"s system.  Proposed (19991222)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Balinsky, Cole, Stracener, Wall  Frech> XF:disney-search-info(3955) | Balinsky> The go.express.com web site does not mention the existence of the Express web server mentioned in the advisory. There appears to be no way of verifying this.  View
990  CVE-1999-1010  Entry  An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.        View

Page 198 of 20943, showing 5 records out of 104715 total, starting on record 986, ending on 990

Actions