CVE List

Id CVE No. Status Description Phase Votes Comments Actions
905  CVE-1999-0925  Candidate  UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers.  Modified (20020829-01)  ACCEPT(2) Baker, Stracener | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Levy  Frech> XF:unitymail-web-dos(1630) | Christey> BID:1760 | URL:http://www.securityfocus.com/bid/1760 | Christey> Affected version is 2.0 | Change date of Bugtraq post - it was 1998.  View
549  CVE-1999-0564  Candidate  An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn"t require a password) or to become disabled.  Proposed (19990728)  ACCEPT(2) Baker, Shostack | NOOP(1) Northcutt    View
228  CVE-1999-0229  Candidate  Denial of service in Windows NT IIS server using ....  Modified (19991228-02)  ACCEPT(2) Baker, Shostack | MODIFY(2) Frech, Wall | NOOP(1) Northcutt | REJECT(1) Christey | REVIEWING(1) Levy  Wall> Denial of service in Windows NT IIS Server 1.0 using ..... | Source: Microsoft Knowledge Base Article Q115052 - IIS Server. | Frech> XF:http-dotdot (not necessarily IIS?) | Christey> DELREF XF:http-dotdot - it deals with a read/access dot dot | problem. | Christey> This actually looks like XF:iis-dot-dot-crash(1638) | http://xforce.iss.net/static/1638.php | If so, include the version number (2.0) | | CHANGE> [Christey changed vote from REVOTE to REJECT] | Christey> Bill Wall intended to suggest Q155052, but the affected | IIS version there is 1.0; the effect is to read files, | so this sounds like a directory traversal problem, | instead of an inability to process certain strings. | | As a result, this candidate is too general, since it could | apply to 2 different problems, so it should be REJECTed. | Christey> Consider adding BID:2218  View
537  CVE-1999-0547  Candidate  An SSH server allows authentication through the .rhosts file.  Proposed (19990728)  ACCEPT(2) Baker, Shostack | MODIFY(1) Frech | NOOP(1) Northcutt  Frech> XF:sshd-rhosts(315)  View
1656  CVE-2000-0078  Candidate  The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.  Modified (20090302)  ACCEPT(2) Baker, Prosser | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> ADDREF XF:hp-aserver | Christey> The Bugtraq posting does not mention specific versions. | Is June 1999 equivalent to HP-UX 10.x? | Prosser> The HP Bulletin (already ref"d) just specifies 10.x and 11.x OS versions running on HP9000 700/800 series. According to Tripp (bugtraq), the audio server doesn"t run on a machine without Audio Hardware (logical). So one has to assume from the bulletin that any 9000 with audio hardware that is running a 10.x or 11.x version of OS with either the 98 or 99 version of Aserver loaded will be vulnerable to either the exploit in CVE-1999-0005(the 98 version of Aserver) or CVE-2000-0078 (the 99 version)and should take appropriate action. No patches out from HP as of 10/2/2000 so either remove the program or tighten the permissions considerably. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:1929 | Make sure not dupe"s with CVE-2000-0005 and CVE-20000-0077.  View

Page 20139 of 20943, showing 5 records out of 104715 total, starting on record 100691, ending on 100695

Actions