CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
986 | CVE-1999-1006 | Candidate | Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter. | Proposed (19991222) | ACCEPT(4) Baker, Cole, Prosser, Stracener | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:groupwise-web-path | Prosser> Pretty well confirmed by testing with responses to BugTraq list. | | additional ref: BugTraq ID 879 http://www.securityfocus.com/bid/879 | Christey> A later discovery almost 2 years later is at: | BUGTRAQ:20020227 SecurityOffice Security Advisory:// Novell | GroupWise Web Access Path Disclosure Vulnerability | http://marc.theaimsgroup.com/?l=bugtraq&m=101494830315071&w=2 | CD:SF-LOC might suggest merging these together. | View |
987 | CVE-1999-1007 | Entry | Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file. | View | |||
988 | CVE-1999-1008 | Entry | xsoldier program allows local users to gain root access via a long argument. | View | |||
989 | CVE-1999-1009 | Candidate | The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user"s system. | Proposed (19991222) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Balinsky, Cole, Stracener, Wall | Frech> XF:disney-search-info(3955) | Balinsky> The go.express.com web site does not mention the existence of the Express web server mentioned in the advisory. There appears to be no way of verifying this. | View |
990 | CVE-1999-1010 | Entry | An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy. | View |
Page 198 of 20943, showing 5 records out of 104715 total, starting on record 986, ending on 990