CVE List

Id CVE No. Status Description Phase Votes Comments Actions
611  CVE-1999-0629  Candidate  The ident/identd service is running.  Proposed (19990721)  ACCEPT(2) Baker, Ozancin | MODIFY(1) Frech | NOOP(2) Christey, Wall | REJECT(1) Northcutt  Frech> possibly XF:identd? | Christey> XF:ident-users(318) ? | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:identd-vuln(61) | XF:ident-users(318)  View
474  CVE-1999-0476  Candidate  A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user.  Proposed (19990721)  ACCEPT(3) Baker, Frech, Ozancin | NOOP(3) LeBlanc, Northcutt, Wall    View
497  CVE-1999-0499  Candidate  NETBIOS share information may be published through SNMP registry keys in NT.  Proposed (19990721)  ACCEPT(5) Baker, Northcutt, Ozancin, Shostack, Wall | MODIFY(1) Frech | REJECT(1) LeBlanc  Frech> Change wording to "Windows NT." | XF:snmp-netbios | LeBlanc> Share info can be obtained via SNMP queries, but I question | whether this is a vulnerability. The system can be configured not to do | this, and one may argue that SNMP itself is an insecure configuration. | Furthermore, the share information isn"t published via registry keys - | the description could refer to more than one actual issue. SNMP is meant | to allow people to obtain information about systems. I"m willing to | discuss this with the rest of the board.  View
256  CVE-1999-0257  Candidate  Nestea variation of teardrop IP fragmentation denial of service.  Proposed (19990726)  ACCEPT(1) Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:nestea-linux-dos | Christey> Not sure how many separate "instances" of Teardrop | and its ilk. Also see comments on CVE-1999-0001. | | See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258 | | Is CVE-1999-0001 the same as CVE-1999-0052? That one is related | to nestea (CVE-1999-0257) and probably the one described in | BUGTRAQ:19981023 nestea v2 against freebsd 3.0-Release | The patch for nestea is in ip_input.c around line 750. | The patches for CVE-1999-0001 are in lines 388&446. So, | CVE-1999-0001 is different from CVE-1999-0257 and CVE-1999-0052. | The FreeBSD patch for CVE-1999-0052 is in line 750. | So, CVE-1999-0257 and CVE-1999-0052 may be the same, though | CVE-1999-0052 should be RECAST since this bug affects Linux | and other OSes besides FreeBSD. | | Also see BUGTRAQ:19990909 CISCO and nestea. | | Finally, note that there is no fundamental difference between | nestea and nestea2/nestea-v2; they are different ports that | exploit the same problem. | | The original nestea advisory is at | http://www.technotronic.com/rhino9/advisories/06.htm | but notice that the suggested fix is in line 375 of | ip_fragment.c, not ip_input.c. | Christey> See the SCO advisory at: | http://www.securityfocus.com/templates/advisory.html?id=1411 | which may further clarify the issue. | Christey> BUGTRAQ:19980501 nestea does other things | http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925819&w=2 | BUGTRAQ:19980508 nestea2 and HP Jet Direct cards. | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925870&w=2 | BUGTRAQ:19981027 nestea v2 against freebsd 3.0-Release | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90951521507669&w=2 | | Nestea source code is in | MISC:http://oliver.efri.hr/~crv/security/bugs/Linux/ipfrag6.html  View
257  CVE-1999-0258  Candidate  Bonk variation of teardrop IP fragmentation denial of service.  Proposed (19990726)  MODIFY(2) Frech, Wall | REVIEWING(1) Christey  Wall> Reference Q179129 | Frech> XF:teardrop-mod | Christey> Not sure how many separate "instances" of Teardrop there are. | See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258 | Christey> See the SCO advisory at: | http://www.securityfocus.com/templates/advisory.html?id=1411 | which may further clarify the issue. | Christey> BUGTRAQ:19980108 bonk.c | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88429524325956&w=2 | NTBUGTRAQ:19980108 bonk.c | URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=88433857200304&w=2 | NTBUGTRAQ:19980109 Re: Bonk.c | URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=88441302913269&w=2 | NTBUGTRAQ:19980304 Update on wide-spread NewTear Denial of Service attacks | URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=88901842000424&w=2 | BUGTRAQ:19980304 Update on wide-spread NewTear Denial of Service attacks | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88903296104349&w=2 | CIAC:I-031a | http://ciac.llnl.gov/ciac/bulletins/i-031a.shtml | | CERT summary CS-98.02 implies that bonk, boink, and newtear | all exploit the same vulnerability.  View

Page 20528 of 20943, showing 5 records out of 104715 total, starting on record 102636, ending on 102640

Actions