CVE List

Id CVE No. Status Description Phase Votes Comments Actions
824  CVE-1999-0844  Candidate  Denial of service in MDaemon WorldClient and WebConfig services via a long URL.  Proposed (19991208)  ACCEPT(2) Baker, Stracener | MODIFY(2) Cole, Frech | NOOP(1) Armstrong | RECAST(1) Christey | REVIEWING(1) Prosser  Cole> 823 and 820 are two different vulnerabilities and should be | separated out. They are both buffer overflows but accomplish it in a | different fashion and the end exploit is different. | Frech> (RECAST?) | XF:mdaemon-worldclient-dos | XF:mdaemon-webconfig-dos | Recast request: This is really two services exhibiting the same problem. | Christey> as suggested by others. | | Also see confirmation at: | http://mdaemon.deerfield.com/helpdesk/hotfix.cfm  View
825  CVE-1999-0845  Candidate  Buffer overflow in SCO su program allows local users to gain root access via a long username.  Proposed (19991208)  ACCEPT(4) Armstrong, Cole, Prosser, Stracener | MODIFY(1) Frech | RECAST(1) Baker | REVIEWING(1) Christey  Christey> DUPE CVE-1999-0317? | Frech> XF:sco-su-username-bo | Christey> ADDREF BID:826 | CONFIRM:ftp://ftp.sco.com/SSE/sse039.tar.Z  View
826  CVE-1999-0846  Candidate  Denial of service in MDaemon 2.7 via a large number of connection attempts.  Proposed (19991208)  ACCEPT(5) Armstrong, Baker, Cole, Prosser, Stracener | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:mdaemon-dos | Christey> CVE-1999-0844 is confirmed by MDaemon at | http://mdaemon.deerfield.com/helpdesk/hotfix.cfm but there | is no apparent confirmation for this problem, even | though it was posted the same day. | Prosser> Looks like from a follow-on message on Bugtraq from Nobuo | <http://www.securityfocus.com/templates/archive.pike?list=1&date=1999-11-28&msg=199912011604.HJI39569.BX-NOJ@lac.co.jp> Deerfield sent a reply about the | DoS problems in MDaemon 2.8.5, that also talks about fixing the 2.7 J DoS | that Nobuo initially reported. Can"t find the original message, so may have | been limited distro. Looks like an upgrade to the latest release might be | the final solution here.  View
830  CVE-1999-0850  Candidate  The default permissions for Endymion MailMan allow local users to read email or modify files.  Proposed (19991208)  ACCEPT(2) Cole, Stracener | MODIFY(1) Frech | NOOP(2) Armstrong, Baker | REVIEWING(1) Prosser  Frech> XF:endymion-mailman-perms  View
832  CVE-1999-0852  Candidate  IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.  Proposed (19991208)  ACCEPT(3) Armstrong, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(1) Prosser  Frech> XF:websphere-protect  View

Page 20551 of 20943, showing 5 records out of 104715 total, starting on record 102751, ending on 102755

Actions