CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
756 | CVE-1999-0776 | Candidate | Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack. | Proposed (19991214) | ACCEPT(4) Frech, Levy, Ozancin, Stracener | MODIFY(1) Baker | NOOP(6) Armstrong, Blake, Cole, Landfield, LeBlanc, Wall | REVIEWING(1) Christey | Christey> This candidate is unconfirmed by the vendor. | | Posted by Arne Vidstrom. | Blake> I"d like to change my vote on this from ACCEPT to NOOP. I did some | digging and the vendor seems to have discontinued the product, so no | information is available beyond Arne"s post. Unless Andre has a copy | in his archive and can test it, I think we have to leave it out. | Wall> I agree with Blake. We have not seen the product and it has been discontinued. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> If this is (or was) tested by some tool, we should ACCEPT it. | Baker> http://www.securityfocus.com/bid/270 | Christey> BID:270 | URL:http://www.securityfocus.com/bid/270 | View |
775 | CVE-1999-0795 | Candidate | The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches. | Proposed (19991222) | ACCEPT(2) Baker, Stracener | MODIFY(1) Frech | NOOP(1) Ozancin | Frech> XF:sun-nisplus | View |
778 | CVE-1999-0798 | Candidate | Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type. | Proposed (19991222) | ACCEPT(3) Baker, Ozancin, Stracener | MODIFY(1) Frech | NOOP(1) Christey | Christey> Is CVE-1999-0389 a duplicate of CVE-1999-0798? CVE-1999-0389 | has January 1999 dates associated with it, while CVE-1999-0798 | was reported in late December. | | http://marc.theaimsgroup.com/?l=bugtraq&m=91278867118128&w=2 | | SCO appears to have acknowledged this as well: | ftp://ftp.sco.com/SSE/security_bulletins/SB-99.01a | | The poster also claims that OpenBSD fixed this as well. | Frech> XF:bootp-remote-bo | Christey> Further analysis indicates that this is a duplicate of CVE-1999-0799 | CHANGE> [Christey changed vote from REJECT to NOOP] | Christey> What was I thinking? Brian Caswell pointed out that this is | *not* the same bug as CVE-1999-0799. As reported in the | 1998 Bugtraq post, the bug is in bootpd.c, and is related | to providing an htype value that is used as an index | into an array, and exceeds the intended boundaries of that | array. | View |
648 | CVE-1999-0667 | Candidate | The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service. | Proposed (19991222) | ACCEPT(2) Blake, Cole | MODIFY(1) Stracener | NOOP(2) Baker, Christey | REJECT(1) Frech | Stracener> Add Ref: BUGTRAQ:19970919 Playing redir games with ARP and ICMP | Frech> Cannot proceed without a reference. Too vague, and resembles XF:netbsd-arp: | CVE-1999-0763: NetBSD on a multi-homed host allows ARP packets on one | network to modify ARP entries on another connected network. | CVE-1999-0764: NetBSD allows ARP packets to overwrite static ARP entries. | Will reconsider if reference provides enough information to render a | distinction. | Christey> This particular vulnerability was exploited by an attacker | during the ID"Net IDS test network exercise at the SANS | Network Security "99 conference. The attacker adapted a | publicly available program that was able to spoof another | machine on the same physical network. | | See http://marc.theaimsgroup.com/?l=bugtraq&m=87602880019797&w=2 | for the Bugtraq reference that Tom Stracener suggested. | This generated a long thread on Bugtraq in 1997. | Blake> I"ll second Tom"s request to add the reference, it"s a very | posting good and the vulnerability is clearly derivative of | the work. | | (I do recall talking to the guy and drafting a description.) | View |
654 | CVE-1999-0673 | Candidate | Buffer overflow in ALMail32 POP3 client via From: or To: headers. | Proposed (19991222) | ACCEPT(6) Baker, Blake, Cole, Collins, Levy, Wall | MODIFY(2) Frech, Stracener | NOOP(3) Armstrong, Landfield, Oliver | REVIEWING(1) Ozancin | Stracener> AddRef: ShadowPenguinSecurity:PenguinToolbox,No.037 | Frech> XF:almail-bo | CHANGE> [Cole changed vote from NOOP to ACCEPT] | View |
Page 20556 of 20943, showing 5 records out of 104715 total, starting on record 102776, ending on 102780