CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2485  CVE-2000-0916  Candidate  FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.  Proposed (20001129)  ACCEPT(2) Cole, Mell | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:tcp-seq-predict(139) | Christey> Abstraction issue: CVE-1999-0077 is for TCP sequence | prediction as a general problem; but here we have a specific | implementation flaw.  View
2484  CVE-2000-0915  Entry  fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.        View
2483  CVE-2000-0914  Entry  OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.        View
2482  CVE-2000-0913  Entry  mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.        View
2481  CVE-2000-0912  Entry  MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter.        View

Page 20447 of 20943, showing 5 records out of 104715 total, starting on record 102231, ending on 102235

Actions